Telegram Desktop 在 6.9.4 之前存在 HTML 导出功能中的跨站脚本(XSS)漏洞(首个修复该问题的稳定版本为 7.0.1)。该漏洞位于 export_output_html.cpp 文件中的 button.text.toUtf8 代码处。只有当受害者使用 HTML 导出功能时,攻击者才能利用此漏洞。然而,如果群组成员将包含恶意载荷的消息转发到群组中,则恶意载荷可被导出并触发漏洞(且无需该消息的原始作者为该群组成员)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Telegram | Telegram Desktop | 4.15.1< 6.9.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Telegram | Telegram Desktop | 4.15.1 ~ 6.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet