Initiative是Morelitea开源的一个项目管理平台。 Initiative 0.32.2之前版本存在安全漏洞,该漏洞源于上传的文档可通过公开访问的/uploads/目录获取,无需任何身份验证或授权检查,可能导致敏感文档泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Morelitea | initiative | < 0.32.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28274 | 8.7 HIGH | Initiative Vulnerable to Token Theft via Stored XSS in Document Uploads |
| CVE-2026-28275 | 8.1 HIGH | Initiative Vulnerable to Improper Session Invalidation (JWT Remains Valid) |
No comments yet