You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Arbitrary file read via path traversal in /api/export/exportResources
Stored XSS and arbitrary file write in the host via /api/asset/upload
SSTI via /api/template/renderSprig
Not considered as vulnerabilities:
Stored XSS via /upload
The upload interface can upload any file without checking the file content. If the uploaded file can be opened in SiYuan and causes XSS, please provide more details.
Is there an existing issue for this?
Can the issue be reproduced with the default theme (daylight/midnight)?
Could the issue be due to extensions?
Describe the problem
As requested from the maintainer, here's the titles of the vulnerabilities:
Expected result
n/a
Screenshot or screen recording presentation
No response
Version environment
Log file
n/a
More information
The details has been sent to the maintainer
The text was updated successfully, but these errors were encountered: