漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to the patched release. Notification messages containing user-controlled convert names were rendered in the notification bell dropdown using innerHTML without adequate sanitization. An attacker able to create or influence a convert name that is included in a notification could inject arbitrary JavaScript, which would execute in the browser of an authenticated user when they opened the notification panel. Successful exploitation could allow the attacker to perform actions in the victim's session or access information available to the application in the browser context. The issue was remediated by constructing notification elements through DOM methods and assigning notification message content via textContent instead of innerHTML. This vulnerability was only present on a development branch.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/S:N/RE:L/U:Clear
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
CTI-Transmute 安全漏洞
Vulnerability Description
CTI-Transmute是MISP Project开源的一款网络威胁情报格式转换服务。 CTI-Transmute存在安全漏洞,该漏洞源于通知面板中通知消息包含用户控制的转换名称,使用innerHTML渲染且未进行充分清理,可能导致能够创建或影响通知中包含的转换名称的攻击者注入任意JavaScript,在认证用户打开通知面板时执行,成功利用可允许攻击者在受害者会话中执行操作或访问浏览器环境中应用程序可用的信息。
CVSS Information
N/A
Vulnerability Type
N/A