Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cross-site Scripting (XSS)
Vulnerability Description
This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Vulnerability Type
N/A
Vulnerability Title
hellojs 跨站脚本漏洞
Vulnerability Description
hellojs是个人开发者的一个JavaScript编写的客户端用于用户Oauth认证的软件开发工具包。 hellojs 1.18.6之前版本存在安全漏洞,该漏洞源于代码从url重定向param oauth并将其传递到位置没有任何检查。
CVSS Information
N/A
Vulnerability Type
N/A