脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Potential mXSS vulnerability due to improper HTML escaping in svelte
脆弱性説明
svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is different from what Svelte expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS). More specifically, this can occur when injecting malicious content into an attribute within a `noscript` tag. This issue has been addressed in release version 4.2.19. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
脆弱性タイプ
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
脆弱性タイトル
Svelte 跨站脚本漏洞
脆弱性説明
Svelte是Svelte开源的一种构建 Web 应用程序的新方法。 Svelte 4.2.19及之前版本存在跨站脚本漏洞,该漏洞源于服务器端渲染时HTML转义不当,可能导致变异跨站脚本攻击,尤其是在noscript标签的属性中注入恶意内容时。
CVSS情報
N/A
脆弱性タイプ
N/A