漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Stored XSS via html file upload in convos
Vulnerability Description
Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS. Also, after uploading a file the XSS attack is triggered upon a user viewing the file. Through this vulnerability, an attacker is capable to execute malicious scripts. Users are advised to update as soon as possible.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Nordaaker Convos 跨站脚本漏洞
Vulnerability Description
Nordaaker Convos是挪威Nordaaker公司的一款基于Web浏览器的开源多用户聊天应用程序。 Nordaaker Convos存在跨站脚本漏洞,该漏洞源于软件对于SVG扩展名文件限制存在问题。攻击者可以上传扩展名为.html的文件。通过上传带有html扩展名的SVG文件,可以绕过上传过滤器。这会导致存储型跨站脚本漏洞。此外,在上传文件后,当用户查看文件时,会触发跨站脚本攻击。通过该漏洞,攻击者能够执行恶意脚本。
CVSS Information
N/A
Vulnerability Type
N/A