Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Stored XSS via javascript URI in Apollo Change Requests comment
Vulnerability Description
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Vulnerability Type
Web页面编码URIScheme转义处理不恰当
Vulnerability Title
Palantir Apollo 跨站脚本漏洞
Vulnerability Description
Palantir是美国Palantir公司的一个数据平台,通过消除后端数据管理和前端数据分析之间的障碍来重新构想人们如何使用数据。 Palantir Apollo存在跨站脚本漏洞,该漏洞源于Apollo change requests功能存在跨站脚本(XSS)漏洞。
CVSS Information
N/A
Vulnerability Type
N/A