Netease Youdao QAnything Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in Netease Youdao QAnything, affecting all versions prior to the fix. This vulnerability allows attackers to upload malicious knowledge files to the knowledge base, which can then trigger XSS attacks during user chats.
Impact
Exploitation of this vulnerability allows for the execution of malicious JavaScript code in the context of the user's browser, potentially leading to hijacking the victim's browser session.
Reproduction
To reproduce this vulnerability, first upload a file containing malicious JavaScript into the document collection of a created knowledge base. Then, engage in a conversation with the QAnything service, which will trigger the XSS attack by executing the uploaded JavaScript.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
