Steedos 平台版本 3.0.15-beta.47 存在一个反射型跨站脚本(XSS)漏洞,该漏洞位于匿名的 端点。该端点未对查询参数进行适当的转义,特别是在内联脚本元素中。攻击者可以构造包含脚本终止序列的恶意链接,通过 或 参数,在受害者的会话中执行任意 JavaScript 代码,并窃取 凭证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| steedos | steedos-platform | 0 ~ 3.0.15-beta.47 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet