lissy93 dashy是lissy93个人开发者开源的一个可以部署在自己服务器上的个人导航/监控面板。 lissy93 dashy 4.3.7之前版本存在跨站脚本漏洞,该漏洞源于workspace视图信任url查询参数并直接分配给iframe源,缺少方案验证,可能导致已登录用户打开特制工作区链接时,JavaScript在Dashy源上运行并读取同源浏览器数据、与Dashy DOM交互以及代表受害者发送请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Dashy versions up to 4.3.6 contain a reflected cross-site scripting vulnerability in the workspace view. The url query parameter is passed directly to an iframe src attribute without scheme validation, allowing an attacker to inject javascript: URIs that execute arbitrary JavaScript in the context of the Dashy origin. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-55592.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet