Hoppscotch是Hoppscotch开源的一个Api开发生态系统。 hoppscotch 2026.3.0之前版本存在输入验证错误漏洞,该漏洞源于/enter页面中的redirect查询参数未经适当验证直接用于构建URL,可能导致DOM型开放重定向。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| hoppscotch | hoppscotch | < 2026.3.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Hoppscotch <= 2026.2.1 is vulnerable to a DOM-based open redirect on the /enter page. The redirect query parameter is passed directly to windowz location.href with no origin validation. Requires one additional query parameter to trigger. Exploited via a crafted URL such as /enter?redirect=evil.com&foo=bar. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-34847.yaml | POC详情 |
| 2 | Appsmith <= v1.97 instance management API endpoints are accessible without authentication, allowing an attacker to obtain sensitive information such as license plan, instance ID, authentication providers, feature flags, and configuration metadata via unauthenticated requests to specific API endpoints. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/appsmith/appsmith-info-disclosure.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2026-34848 | 5.4 MEDIUM | Hoppscotch 跨站脚本漏洞 |
| CVE-2026-34931 | Hoppscotch 输入验证错误漏洞 | |
| CVE-2026-34932 | Hoppscotch 跨站脚本漏洞 |
暂无评论