Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:") before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
oauth2-server 输入验证错误漏洞
Vulnerability Description
oauth2-server是个人开发者的一个符合标准的用 PHP 编写的 OAuth 2.0 授权服务器的实现。为应用程序提供身份验证和授权功能,保护API安全。 oauth2-server(node-oauth2-server)3.1.1版本及之前版本存在安全漏洞。攻击者利用该漏洞在发出授权请求时通过redirect_uri参数传递跨站脚本有效载荷。
CVSS Information
N/A
Vulnerability Type
N/A