漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Frappe LMS: HTML injection in user-controlled metadata
Vulnerability Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.
CVSS Information
N/A
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
Frappe Learning Management System 注入漏洞
Vulnerability Description
Frappe Learning Management System是Frappe开源的一个易于使用的开源学习管理系统。 Frappe Learning Management System 2.53.0之前版本存在注入漏洞,该漏洞源于经过身份验证的用户可在某些用户可编辑字段中提供特制内容,导致页面元数据中显示时访问者浏览器导航至攻击者选择的URL。
CVSS Information
N/A
Vulnerability Type
N/A