漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HtmlSanitizer has a bypass via template tag
Vulnerability Description
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Vulnerability Type
对输出编码和转义不恰当
Vulnerability Title
HTMLSanitizer 安全漏洞
Vulnerability Description
HTMLSanitizer是JuliaHub开源的一个HTML格式化软件。 HTMLSanitizer 9.0.892之前版本和9.1.893-beta之前版本存在安全漏洞,该漏洞源于允许template标签时未清理其内容,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A