OWASP ESAPI是一个免费的、开源的、Web 应用程序安全控制库,使程序员可以更轻松地编写风险较低的应用程序。 OWASP ESAPI(OWASP Enterprise Security API)2.3.0.0 之前版本存在安全漏洞,该漏洞源于antisamy-esapi.xml 配置文件中的“onsiteURL”正则表达式不正确,可能导致“javascript:”URL未能正确清理。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ESAPI | esapi-java-legacy | <= 2.2.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/shoucheng3/ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet