Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Beaker 安全漏洞
Vulnerability Description
Beaker是一套开源的可对实验室的测试计算机提供管理和自动化功能的软件。 Beaker 20.1之前的版本中的bkr/server/widgets.py文件的搜索栏代码存在安全漏洞,该漏洞源于程序没有充分过滤用户提交的输入。当用户浏览受影响的网站时,其浏览器将执行攻击者提供的任意HTML或脚本代码。这可能导致攻击者窃取基于cookie的身份验证或控制站点呈现给用户的方式。
CVSS Information
N/A
Vulnerability Type
N/A