WWBN AVideo 30.0 及之前版本(以及 master 分支上截至 commit 4cb576e 的代码)在 中存在跨站请求伪造(CSRF)漏洞。该接口仅校验用户是否已登录,并通过 GET 请求从 中读取 、 和 参数,但未强制要求 CSRF 令牌或来源检查。攻击者若能将已登录的直播主诱导至一个恶意页面,即可在用户不知情的情况下修改其直播频道的观众重定向设置(该设置保存在 中),从而导致观众被重定向至钓鱼网站,或被展示伪造的消息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet