Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Content Injection
Vulnerability Description
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerability, assuming an attacker can influence the value entered into the template. If the template is used to render user-generated content, this vulnerability may escalate to a persistent XSS vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Crow 跨站脚本漏洞
Vulnerability Description
Crow是一个用于运行 Web 服务的 C++ 微框架。 Crow 存在安全漏洞,攻击者可利用该漏洞可以操纵输入以引入额外的属性从而可能执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A