在电子邮件媒体类型的 OAuth 表单中,授权端点值被直接传递给 ,而未对 URL 方案进行验证,从而导致浏览器中执行 协议的 URL。这意味着,通过精心构造的媒体类型配置(可随导入文件交付),攻击者可以以授予同意的超级管理员(Super Admin)身份执行任意 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59782 | 6.9 MEDIUM | JavaScript preprocessing memory disclosure |
| CVE-2026-59786 | 6.9 MEDIUM | Active agent heartbeat missing TLS check |
| CVE-2026-59787 | 5.3 MEDIUM | SNMP trap injection in zabbix_trap_receiver.pl |
| CVE-2026-59785 | 5.1 MEDIUM | Hidden host credentials inferable via multiselect.get filtering |
| CVE-2026-59783 | 2.3 LOW | Server DoS via binary items |
No comments yet