Keystone是一款最强大的 Node.js 无头 Cms。用于帮助您比任何其他 Cms 或应用程序框架更快地构建和扩展。 keystone 存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| keystonejs | keystonejs/keystone | unspecified ~ @keystone-6/auth@1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | On the login page, there is a "from=" parameter in URL which is vulnerable to open redirect and can be escalated to reflected XSS. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0087.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet