漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint
Vulnerability Description
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Vulnerability Type
过度许可的跨域白名单
Vulnerability Title
Papermark 配置错误漏洞
Vulnerability Description
papermark是papermark个人开发者开源的一个文档分享平台。 Papermark 0.22.0及之前版本存在配置错误漏洞,该漏洞源于跨域资源共享(CORS)配置错误,可能导致未经身份验证的远程攻击者利用基于TUS的查看器上传端点,该端点会将任意请求Origin设置为Access-Control-Allow-Credentials=true,从而执行携带凭据的跨域请求,诱使已验证的用户访问恶意页面以静默上传任意文件到受害者的数据房间并读取带凭据的响应。
CVSS Information
N/A
Vulnerability Type
N/A