NocoBase 在富文本字段的读取渲染器中未能正确清理(sanitize)字段值,这使得拥有创建权限的用户能够存储带有事件处理器的恶意 HTML。攻击者可以通过集合 API 写入任意标记(markup),这些标记将在所有查看受影响记录的用户的浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet