Geomap 面板中 MapLibre 基础图层存在存储型跨站脚本(Stored XSS)漏洞。拥有编辑器(Editor)角色的用户可以托管一个恶意的样式配置,从而在另一位用户的会话中执行任意 JavaScript 代码,并借此将权限提升至组织管理员(Org Admin)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 12.3.0 | - |
|
| Grafana | Grafana Enterprise | 12.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet