Sakai 是一个协作与学习环境(CLE)。在版本 23.0 至 23.5 之前,以及版本 25.0 至 25.3 之前的版本中,Sakai 的“对话”(Conversations)工具在存储主题和帖子消息时未进行 HTML 净化处理,且前端使用 LitElement 的 指令渲染这些内容,从而导致存储型跨站脚本攻击(Stored XSS)。任何拥有访问权限且该站点启用了“对话”工具的用户,均可注入任意 HTML 和 JavaScript 代码,这些代码将在所有查看该主题或帖子的其他用户的浏览器中执行。此问题已在版
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sakaiproject | sakai | >= 23.0, < 23.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet