CNNVD-202601-3286 Information
Jan 20, 2026
cve
CNNVD ID
CNNVD-202601-3286
Related CVE
- CNNVD Published: 2026-01-20
Description (Chinese)
Sesame是Sesame公司的一个Web应用。 Sesame存在跨站脚本漏洞,该漏洞源于上传的SVG图像清理不当,可能导致攻击者嵌入恶意脚本,并在用户访问受感染资源时执行。
Description (English)
Sesame is a Web application of Sesame. Sesame has a cross-site script loophole, which stems from the inappropriate clean-up of uploaded SVG images, which may result in the attackers embedding a malicious script and implementing it when users access infected resources.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
Sesame
Published
2026-01-20
Last Modified
2026-02-24