漏洞标题
文件上传本地预览在用户交互后可以运行嵌入的脚本
漏洞描述信息
文件上传本地预览在用户交互后可以运行嵌入脚本
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
漏洞类别
N/A
漏洞标题
File upload local preview can run embedded scripts after user interaction
漏洞描述信息
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0.
CVSS信息
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
漏洞类别
输出中的特殊元素转义处理不恰当(注入)
漏洞标题
Travis Ralston matrix-react-sdk 代码问题漏洞
漏洞描述信息
Travis Ralston matrix-react-sdk是 (Travis Ralston)开源的一个应用软件。用于将Matrix聊天/语音客户端插入网页。 Matrix-React-SDK 存在代码问题漏洞,该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
CVSS信息
N/A
漏洞类别
代码问题