Fabasoft Folio Client 2026 版本之前的版本存在安全漏洞。该组件为本地安装的软件,通过网页消息机制与 Fabasoft 浏览器扩展进行通信,但默认情况下未限制哪些网页源(web origins)可以调用其功能。注册表项 VALIDDOMAINS 用于限制允许访问的网页源,但该值在默认情况下为可选且为空,导致所有域名都被信任。因此,安装了 Fabasoft Folio Client 和浏览器扩展的用户在访问任何网站时,这些网站都有可能调用客户端的功能,例如与下载文档、打开文档以及同步文件相关的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fabasoft | Folio Client | 0 ~ 2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet