Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive information about the IdentityServer authorization response.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IdentityServer3 authorize response页面跨站脚本漏洞
Vulnerability Description
IdentityServer3是一个基于.NET的对Web应用程序进行访问控制的插件。authorize response page是其中的一个授权响应页面。 IdentityServer3中的authorize response page的Angular表达式存在跨站脚本漏洞。远程攻击者可利用该漏洞获取有关IdentityServer授权响应的敏感信息。以下版本受到影响:IdentityServer3 2.4.x版本,2.5.x版本,2.6.1之前的2.6.x版本。
CVSS Information
N/A
Vulnerability Type
N/A