Hyve5 Leantime 3.9.8 及更早版本中已发现一个安全漏洞。该漏洞影响项目仪表盘组件中文件 的某项未知功能。通过利用此漏洞,攻击者可执行跨站脚本攻击(XSS),且攻击可远程发起。相关利用方式已公开披露,可能被恶意利用。 攻击者需具备“编辑权限”(EDIT perm)才能植入恶意载荷;一旦植入,任何查看该项目仪表盘的用户均会触发跨用户攻击,因为被污染的标签名称未经转义即被直接输出到页面中。 研究人员已就此漏洞披露事宜提前联系厂商,但对方未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet