Siber Alem / Detail / 457 / Cve-2026-65605-siyuan-before-v3-7-2-stored-xss-to-rce-via-attribute-view
vuln_report_viewer.sh
VULN REPORT / web uygulamaları / ID: 457

CVE-2026-65605 - SiYuan before v3.7.2 Stored XSS to RCE via Attribute View

2026-07-28
5 görüntülenme
CVE-2026-65605
3.1
CVSS Severity Index Low Severity / Düşük Seviye

Özet

Bu kayit, hedef sistemde bulunan CVE-2026-65605 zafiyetini detaylandirmaktadir. CRITICAL (CVSS 3.1) seviyesinde olan bu zafiyet Products surumlerini etkilemektedir. 28.07.2026 tarihinde yayinlanmistir. v3.7.2'den önceki SiYuan, Öznitelik Görünümü (veritabanı) hücre oluşturmada depolanmış bir siteler arası komut dosyası çalıştırma güvenlik açığı içeriyor. Bir Şablon sütunu değeri,...

exploit_457.txt
<div class="space-y-6 font-sans select-text text-left"><div class="bg-[#1C1C1E] border border-white/5 rounded-lg p-5"><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="info" class="w-3.5 h-3.5 text-[#26A269]"></i>Zafiyet Ozet Bilgileri</h3><div class="grid grid-cols-1 md:grid-cols-2 gap-4 text-sm"><div class="flex items-center gap-2"><span class="text-white/40">Zafiyet Kodu:</span><strong class="text-[#FF5F56] font-mono">CVE-2026-65605</strong></div><div class="flex items-center gap-2"><span class="text-white/40">Siddet Derecesi:</span><span class="font-bold font-mono" style="color:#FF5F56">CRITICAL</span></div><div class="flex items-center gap-2"><span class="text-white/40">CVSS Skoru:</span><span class="text-[#FFB800] font-bold font-mono">3.1</span></div><div class="flex items-center gap-2"><span class="text-white/40">Etkilenen Surumler:</span><span class="text-white/80 font-mono text-xs">Products</span></div><div class="flex items-center gap-2"><span class="text-white/40">Yayinlanma Tarihi:</span><span class="text-white/80 font-mono">28.07.2026</span></div></div></div><div><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="file-text" class="w-3.5 h-3.5 text-[#26A269]"></i>Zafiyet Detayı (Turkce)</h3><p class="text-white/70 leading-relaxed text-sm bg-[#1C1C1E]/30 p-4 border border-white/5 rounded-lg">v3.7.2&#039;den önceki SiYuan, Öznitelik Görünümü (veritabanı) hücre oluşturmada depolanmış bir siteler arası komut dosyası çalıştırma güvenlik açığı içeriyor. Bir Şablon sütunu değeri, otomatik kaçış olmadan metin/şablon yoluyla HTML olarak oluşturulur ve EscapeHTML yalnızca HasUnclosedHtmlTag true değerini döndürdüğünde uygulanır; &lt;img&gt; gibi dengeli kendi kendine kapanan etiketler bu kontrol tarafından atlandığından, bir yük …</p></div><div><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="globe" class="w-3.5 h-3.5 text-[#26A269]"></i>Orijinal Aciklama (Ingilizce)</h3><p class="text-white/40 leading-relaxed text-xs bg-[#1C1C1E]/10 p-4 border border-white/5 rounded-lg italic">
    
    
      
        


  
    
      
        
          
          
            
              
                
              
              
                
              
            
            
              
                
              
              
                
              
            
          
          
            
              
              
              
            
          
          
             CVE ID, Product, Vendor ...
          
        
        
          
            
              
            
          
          
            Pricing
          
          
            
              
            
            
              
                
                  
                    Browse by Apps
                  
                  
                     View All Apps
                      
                  
                
              
              
                
                  
                    
                      
                      Splunk
                    
                  
                  
                    
                      
                      Slack
                    
                  
                  
                    
                      
                      Webhook
                    
                  
                  
                    
                      
                      Teams
                    
                  
                  
                    
                      
                      Jira
                    
                  
                  
                    
                      
                      Chrome
                    
                  
                
              
            
          
          
            
              
              
            
          
          
            
              
              
                API
              
            
          
          
              
   </p></div><div><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="external-link" class="w-3.5 h-3.5 text-[#26A269]"></i>Referanslar</h3><div class="bg-[#1C1C1E]/10 p-4 border border-white/5 rounded-lg"><a href="https://cvefeed.io/vuln/detail/CVE-2026-65605" target="_blank" class="text-[#3b82f6] hover:underline font-mono text-xs break-all">https://cvefeed.io/vuln/detail/CVE-2026-65605</a></div></div><div class="border-t border-white/5 pt-4 flex justify-between items-center text-xs"><span class="text-white/30">Otomatik olarak RSS feed'inden ice aktarildi.</span><a href="https://cvefeed.io/vuln/detail/CVE-2026-65605" target="_blank" class="inline-flex items-center gap-1.5 text-[#26A269] hover:underline font-bold transition-all">Kaynagi Goruntule <i data-lucide="external-link" class="w-3.5 h-3.5"></i></a></div></div>

Yazar Profili

Autopilot
Autopilot Seçkin Üye
Tüm Gönderilerini Gör

Kayıt İstatistikleri

Görüntülenme 5
İndirmeler 1
Yorumlar 0
Siber Alem V1 Status: Operational | Exploits: 420 (156 Verified)
Ping: 18ms Lang: TR