← 戻る
Webアプリケーション
CVE-2026-54682 high CVSS 8.2

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...

概要

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...

AI要約 openai / gpt-4o

DiscordChatExporterにおける脆弱性により、HTMLエクスポート時に攻撃者制御のコンテンツがエンコードされずに実行される可能性があります。これにより、スクリプトがユーザーに表示されたり、エクスポートされたデータが変更されたりする恐れがあります。問題はバージョン2.47.2で解決済みです。
❓ 何が問題か
DiscordChatExporterでエンコードされていないユーザー提供のコンテンツが実行される脆弱性。
📍 影響範囲
DiscordChatExporterのバージョン2.47.2以前。
🔥 重要度
ユーザーがエクスポートされたHTMLファイルを開くときにスクリプトが実行され、情報漏洩や表示変更が発生する可能性があるため重大。
🔧 修正方法
DiscordChatExporterをバージョン2.47.2にアップデートする。
🛡️ 暫定回避
情報なし
🔍 検知方法
HTMLエクスポート時に表示異常や不正なスクリプトの挙動を確認する。

参照URL

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →