Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
David Kitchen bluemonday 跨站脚本漏洞
Vulnerability Description
David Kitchen bluemonday是 (David Kitchen)开源的一个应用程序。用于在Go中实现的HTML清理程序。 bluemonday before 1.0.5 存在跨站脚本漏洞,该漏洞源于特定的Go小写转换大写,“script”字符串的保护机制。
CVSS Information
N/A
Vulnerability Type
N/A