漏洞标题
反射式跨站脚本攻击漏洞
漏洞描述信息
反射跨站脚本漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
Reflected Cross-Site-Scripting vulnerability
漏洞描述信息
Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. The issue is patched in Collabora Online 6.4.9-5. Collabora Online 4.2 is not affected.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Collabora Online 跨站脚本漏洞
漏洞描述信息
Collabora Online是 Collabora 的一个应用软件。一个强大的基于 LibreOffice 的在线办公室,支持所有主要的文档、电子表格和演示文件格式。 Collabora Online 6.4.9-5之前版本存在跨站脚本漏洞。该漏洞允许攻击者在创建Collabora Online iframe时将未转义的HTML注入到变量中,并在Collabora Online iframe的上下文中执行脚本。
CVSS信息
N/A
漏洞类别
跨站脚本