漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
listmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover
Vulnerability Description
listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly. This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability. Cross-site request forgery and cross-site scripting chained together can result in improper admin account creation. As of time of publication, no patched versions are available.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Vulnerability Title
listmonk 跨站请求伪造漏洞
Vulnerability Description
listmonk是Kailash Nadh个人开发者的一个具有现代仪表板的高性能、自托管、时事通讯和邮件列表管理器。 listmonk 1.1.0及之前版本存在跨站请求伪造漏洞,该漏洞源于nonce值未验证,可能导致跨站请求伪造和跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A