漏洞信息详情
FreshRSS 跨站脚本漏洞
漏洞简介
FreshRSS是一款开源的、支持自托管的RSS聚合器。
FreshRSS 1.11.1版本中存在跨站脚本漏洞。远程攻击者可借助‘c’或‘a’参数利用该漏洞注入任意的Web脚本或HTML。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://freshrss.org/
参考网址
来源:packetstormsecurity.com
链接:http://packetstormsecurity.com/files/150608/FreshRSS-1.11.1-Cross-Site-Scripting.htmlExploitThird Party AdvisoryVDB Entry
来源:seclists.org
链接:http://seclists.org/fulldisclosure/2018/Dec/3ExploitMailing ListThird Party Advisory
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/45954/ExploitThird Party AdvisoryVDB Entry
来源:www.netsparker.com
链接:https://www.netsparker.com/web-applications-advisories/ns-18-024-multiple-cross-site-scripting-vulnerabilities-in-freshrss/ExploitThird Party Advisory
受影响实体
暂无
补丁
- FreshRSS 跨站脚本漏洞的修复措施<!--2019-1-31-->
还没有评论,来说两句吧...