该产品的 Web 门户允许在新浏览器标签页中打开外部链接。在某些配置下,源窗口保留对新打开页面的访问权限,使得在导航到外部目标时,两个浏览器上下文之间可以相互交互。 该漏洞可能允许攻击者在用户点击恶意外部链接后,操控原本受信任的应用程序窗口。这种操控可能导致用户被重定向到钓鱼页面,从而造成凭证被盗取,或在受信任网站的上下文中促成其他未授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 API Control Plane | 4.5.0 ~ 4.5.0.54 | - |
|
| WSO2 | WSO2 API Manager | 3.2.0 ~ 3.2.0.468 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet