在 NodeBB 4.15.0 之前的版本中,renderEmoji 函数存在一个存储型跨站脚本(Stored XSS)漏洞,该函数未能正确转义 tag.icon.url 和 tag.name 属性。攻击者可以通过构造包含恶意 emoji 标签的 ActivityPub Create/Note 对象,将任意 HTML 和 JavaScript 代码注入到已存储的帖子内容中,从而在查看所有帖子的用户浏览器中执行恶意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet