漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
Vulnerability Description
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
内嵌的恶意代码
Vulnerability Title
webreinvent vaahcms 处理逻辑错误漏洞
Vulnerability Description
webreinvent vaahcms是webreinvent个人开发者开源的一套内容管理系统。 webreinvent vaahcms 2.0.0版本至2.3.4版本存在处理逻辑错误漏洞,该漏洞源于Blade模板中嵌入了恶意混淆的JavaScript有效负载,可能导致远程攻击者执行未授权代码、窃取密码和抓取Web内容。
CVSS Information
N/A
Vulnerability Type
N/A