漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Iframe escape by plugins in Logseq
Vulnerability Description
Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin to execute arbitrary JavaScript in the privileged host context, potentially gaining unauthorized access to filesystem APIs.
While only version v0.10.15 was tested and confirmed as vulnerable, status of other versions is unknown since this issue was not addressed by a patch.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Logseq 跨站脚本漏洞
Vulnerability Description
Logseq是Logseq开源的一个知识管理和协作平台。。 Logseq v0.10.15版本存在跨站脚本漏洞,该漏洞源于沙盒iframe中运行的插件可将任意HTML属性(如事件处理程序)注入到主机DOM中的容器元素,由于内容安全策略被禁用,导致恶意插件可在特权主机环境中执行任意JavaScript,可能获得对文件系统API的未授权访问。
CVSS Information
N/A
Vulnerability Type
N/A