关键漏洞信息 CVE: CVE-2024-27708 Exploit Title: MyNet Date: 10/05/2024 Exploit Author: André Oliveira Vendor Homepage: https://www.airc.pt/ Software Link: https://www.airc.pt/solucoes-servicos/solucoes?segment=MYN Version: <= 26.06 Tested on: Firefox latest version Description The src parameter in MyNet versions 26.06 and earlier is vulnerable to IFrame injection by unauthenticated users due to insufficient input sanitization and output encoding. Proof of Concept (PoC) To reproduce the vulnerability, provide the victim with the following link containing the specific payload in the src parameter. For example: https://host.domain.pt/responsive/?src=https://www.google.com