Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
Vulnerability Description
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to cross-site scripting because the `XSSRequestWrapper::stripXSS` method can be bypassed. Versions 7.4.22, 8.0.9, and 8.1.0 contain patches for this issue. There are no known workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
替代XSS语法转义处理不恰当
Vulnerability Title
Knowage 跨站脚本漏洞
Vulnerability Description
Knowage是意大利Knowage公司的一套用于在传统资源和大数据系统上进行现代业务分析的开源套件。 Knowage 6.xx系列版本、 7.4.22之前版本、8.0.9之前版本、8.1.0之前版本存在安全漏洞,攻击者利用该漏洞可以使用有效负载绕过此过滤器。
CVSS Information
N/A
Vulnerability Type
N/A