Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Streamlit Cross-site Scripting vulnerability
Vulnerability Description
Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app. The attacker could then trick the user into visiting the malicious URL and, if successful, the server would render the malicious javascript payload as-is, leading to XSS. Version 0.81.0 contains a patch for this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Streamlit 跨站脚本漏洞
Vulnerability Description
Streamlit是Streamlit开源的一个面向数据的 Python 应用程序开发框架。 Streamlit 0.81.0之前版本存在跨站脚本漏洞,该漏洞源于存在反射型跨站脚本(XSS)漏洞,攻击者利用该漏洞可以制作带有Javascript负载的恶意URL呈现恶意javascript。
CVSS Information
N/A
Vulnerability Type
N/A