Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password cracking). This occurs in extensions/contentmodel/participants/diagnostics/LSPXMLParserConfiguration.java.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat XML Language Support XML Language Server 跨站脚本漏洞
Vulnerability Description
Red Hat XML Language Support(vscode-xml)是美国红帽(Red Hat)公司的一款支持创建和编辑XML文档的Visual Studio Code扩展。XML Language Server是使用在其中的一个XML语言服务器。 Red Hat XML Language Support 0.9.1之前版本中使用的XML Language Server 0.9.1之前版本存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
CVSS Information
N/A
Vulnerability Type
N/A