Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper handling of empty HTML attributes in html/template
Vulnerability Description
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SUSE go 注入漏洞
Vulnerability Description
SUSE go是德国SUSE公司的一种富有表现力的、并发的、垃圾收集的通用/系统编程语言。 SUSE go 1.20版本存在安全漏洞,该漏洞源于对空HTML属性处理不当。
CVSS Information
N/A
Vulnerability Type
N/A