漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Superset stored XSS on Dashboard markdown
Vulnerability Description
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the user's browser. The javascript code will be automatically executed (Stored XSS) when a legitimate user surfs on the dashboard page. The vulnerability is exploitable creating a “div” section and embedding in it a “svg” element with javascript code.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Apache Superset 跨站脚本漏洞
Vulnerability Description
Apache Superset up是美国 (Apache)公司的一个应用软件。提供大型分布式环境中横向扩展设计。 Apache Superset up to and including 0.38.0 存在安全漏洞,攻击者可利用该漏洞注入javascript代码,在用户浏览器的上下文中执行不需要的操作。
CVSS Information
N/A
Vulnerability Type
N/A