Unblu Spark是瑞士Unblu公司的一种以对话为核心的数字客户体验平台中的一个关键组件。 Unblu Spark 8.36.1及之前版本存在安全漏洞,该漏洞源于开放重定向,可升级为基于DOM的跨站脚本攻击,可能导致注入的JavaScript代码完全访问主应用程序的Cookie、DOM和同源API。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unblu inc. | Unblu Spark | ≤ 8.36.1 |
affected |
8.36.1-hotfix.0 |
unaffected | ||
8.37.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unblu inc. | Unblu Spark | 0 ~ 8.36.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet