Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2023-49950 PoC — Logpoint SIEM 跨站脚本漏洞

Source
Associated Vulnerability
Title:Logpoint SIEM 跨站脚本漏洞 (CVE-2023-49950)
Description:The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.
Description
A write-up detailing CVE-2023-49950. Affects Logpoint SIEM v6.1.0-v7.3.0
File Snapshot

[4.0K] /data/pocs/941e9cc162c9f978516615b1c736ca49e83df696 └── [ 13K] cve-2023-49950.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →