在 Governikus AusweisApp 2.5.4 及以下版本中已发现一个安全缺陷。受影响的是组件 StartPAOSResponse Handler 中某个未知功能。对参数 ResultMessage 的操纵可能导致跨站点脚本(XSS)漏洞,该攻击可远程发起。升级到 2.5.5 版本可以解决此问题,建议升级受影响的组件。该 CVE 由供应商申请登记。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Governikus | AusweisApp | 2.5.0 |
cpe:2.3:a:governikus:ausweisapp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet