From da853c23068df0dede74894d51443a8bfe35a7b2 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Sun, 19 Nov 2023 18:41:08 +0800 Subject: [PATCH] =?UTF-8?q?Create=20CVE-2023-4357-Chrome-XXE=E6=BC=8F?= =?UTF-8?q?=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CVE-2023-4357-Chrome-XXE漏洞.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 CVE-2023-4357-Chrome-XXE漏洞.md diff --git a/CVE-2023-4357-Chrome-XXE漏洞.md b/CVE-2023-4357-Chrome-XXE漏洞.md new file mode 100644 index 0000000..cc523aa --- /dev/null +++ b/CVE-2023-4357-Chrome-XXE漏洞.md @@ -0,0 +1,17 @@ + +## CVE-2023-4357-Chrome-XXE漏洞 +CVE-2023-4357-Chrome-XXE +Chrome XXE 漏洞 POC +实现对访客者本地文件读取 + +## 影响版本 +``` +Chrome 版本 < 116.0.5845.96 +Chromium 版本 < 116.0.5845.96 +Electron 版本 < 26.1.0 +``` + +## poc +``` +https://github.com/xcanwin/CVE-2023-4357-Chrome-XXE +```