在 QloApps 1.7.0 及更早版本中,后台列表筛选的 POST 参数被直接渲染到 HTML input 标签的 value 属性中,且未进行转义处理,而该模板为列表辅助模板。攻击者可诱导已认证的用户向列表控制器提交精心构造的 POST 请求,其中包含恶意载荷,从而在受害者的会话中执行任意 JavaScript 代码,进而读取管理员数据并执行相关操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet