SiYuan 3.8.4 之前版本在渲染停靠栏(Dock)树形结构时,未能对从笔记本文件导入的书签标签进行适当的 HTML 转义。攻击者可构造包含未转义 HTML 的恶意 .sy 笔记本文件,利用书签属性中的 XSS 漏洞,在具备子进程(child_process)访问权限的 Electron 渲染进程中执行脚本,从而实现命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet