Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
squidex 跨站脚本漏洞
Vulnerability Description
squidex是一款 Headless CMS 和内容管理中心。 Squidex 7.9.0 之前版本存在跨站脚本漏洞,该漏洞源于SVG 检查中存在不完整的黑名单,允许通过 IFRAME 元素中的 SRC 属性进行跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A