Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Asp.Net Zero 安全漏洞
Vulnerability Description
Asp.Net Zero是一个开源Web开发框架。 Asp.Net Zero 12.3.0 之前版本存在安全漏洞,该漏洞源于消息是通过 websocket 传输的,攻击者利用该漏洞可以在用户消息中进行 HTML 注入,将目标受害者重定向到任何 URL。
CVSS Information
N/A
Vulnerability Type
N/A