Strapi 4.x 至 4.26.2 版本以及 5.x 5.48.1 之前的版本中,内容管理器的 WYSIWYG(所见即所得)预览组件存在存储型跨站脚本(Stored XSS)漏洞,该组件未能从富文本中剥离 标签。拥有作者(Author)角色的用户可以在富文本字段中嵌入恶意的 标签,当编辑者(Editor)或超级管理员(Super Admin)展开预览面板时,这些脚本将在其会话中执行,从而导致账户被接管(account takeover)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet