Shynet安全审计报告 v0.13.1
bishopfox.com | 博客 | #appsec | #vulnerability-research | #security-audit | #web-security | #vulnerability-disclosure | #shynet | #stored-xss | #password-reset-poisoning
摘要
Bishop Fox 对 Shynet 0.13.1 的安全审计发现两个未认证漏洞:通过统计请求 location/referrer 字段注入的存储型 XSS,以及伪造 Host 头的密码重置投毒;0.14.0 已修复。
- 发布时间
- 收录时间
Skip to content