Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Server-side Request Forgery (SSRF)
Vulnerability Description
This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowing for an SSRF attack.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
PhantomJS 代码问题漏洞
Vulnerability Description
PhantomJS是一款用于自动化网页交互的无头浏览器。 phantomjs-seo 所有版本存在安全漏洞,攻击者可利用该漏洞可以创建一个url,并将其传递给一个PhantomJS实例,从而实现SSRF攻击。
CVSS Information
N/A
Vulnerability Type
N/A