漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Grist: XSS through unsafe value interpolation in server-rendered pages
Vulnerability Description
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripting. On the main application page, a document's name or description, set by a document editor, is rendered into the page that other users load when opening the document. On the OAuth2 end-of-flow page, the openerOrigin request parameter was reflected back into the served page. Injected script runs in the victim's Grist origin and can act through the authenticated session, reading or modifying data and changing sharing settings and access rules. A document editor could therefore escalate to owner-level access. This issue is fixed in version 1.7.15.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
gristlabs grist-core 输出处理不当漏洞
Vulnerability Description
gristlabs grist-core是gristlabs公司的一款现代关系电子表格软件。 gristlabs grist-core 1.7.15之前版本存在安全漏洞,该漏洞源于服务器渲染页面未完全转义用户控制的值,容易受到跨站脚本攻击,文档编辑者可能因此提升至所有者级权限。
CVSS Information
N/A
Vulnerability Type
N/A