Takahe 0.11.0 及以下版本未能在联邦化帖子内容和个人资料摘要中的链接 中限制 URL 协议,使得远程攻击者可以注入 链接。攻击者可以投递包含恶意 的联邦内容,当用户点击这些链接时,JavaScript 将在当前实例的域名下执行,从而导致会话劫持或用户身份被冒用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jointakahe | takahe | 0 ~ 0.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet