查看设计页,然后在左上角点击“背景”即可触发漏洞,自动执行JS代码。
以下文本转载自 turbowarp.org
我们发现了Scratch所有版本中的一个严重漏洞。在桌面应用中,打开一个恶意项目可能会在你的电脑上安装勒索软件。
我们两年前就向Scratch报告了这个问题,但至今仍未发布修复补丁。最新的TurboWarp版本不受此影响。更多详情请见我的博客。
We discovered a critical vulnerability in all versions of Scratch. In the desktop app, opening a malicious project could install ransomware on your computer.
We reported this to Scratch two years ago, but no fix has been released yet. The latest TurboWarp is not affected. More details on my blog.
本项目不支持手机或可直接操作
Comment