漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HBAI-Ltd Toonflow-app getCodeByLink Endpoint getCodeByLink.ts fetch server-side request forgery
Vulnerability Description
A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. The manipulation of the argument Link results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. There is ongoing doubt regarding the real existence of this vulnerability. The vendor explains in a reply to the issue report, that "[t]he /getCodeByLink interface is used to obtain TS code and run it locally. It is inherently a high-risk interface, and users must clearly understand the risks before requesting to use it."
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Toonflow 代码问题漏洞
Vulnerability Description
Toonflow是HBAI-Ltd个人开发者的一款AI短剧生产工作台。 Toonflow 1.1.1及之前版本存在代码问题漏洞,该漏洞源于getCodeByLink Endpoint组件中src/routes/setting/vendorConfig/getCodeByLink.ts文件的fetch函数对参数Link操作不当,可能导致服务端请求伪造。攻击者可能远程发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A