Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
Pacparser 注入漏洞
Vulnerability Description
Pacparser是Manu Garg个人开发者的一个用于解析代理自动配置(PAC)文件的库。 Pacparser 1.4.2之前版本存在安全漏洞,该漏洞源于当攻击者控制URL时允许JavaScript注入,并可能允许权限升级。
CVSS Information
N/A
Vulnerability Type
N/A