Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cross-site Scripting (XSS)
Vulnerability Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
Scullyio Scully 注入漏洞
Vulnerability Description
Scullyio Scully是Scullyio组织的一款基于Typescript用于构建Angular应用的软件。Scully将应用中的每个页面预先渲染为纯HTML和CSS。为此,Scully使用guessjs查找项目中的所有路线。然后Scully访问每条路线,渲染视图并将其保存到HTML文件。 Scullyio Scully before 1.0.9 存在安全漏洞,该漏洞源于传输状态用JSON.stringify()函数序列化,然后写入HTML页面。
CVSS Information
N/A
Vulnerability Type
N/A