Vite是Vite开源的一种新型的前端构建工具。 Vite存在跨站脚本漏洞,该漏洞源于通过提供恶意URL查询字符串,可以将任意HTML注入输出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Vite's dev server, when used with `appType: 'custom'` and manually invoking `server.transformIndexHtml` using the unmodified request URL, is vulnerable to XSS via a crafted URL payload. If the HTML being served includes an inline module script (`<script type="module">...</script>`), an attacker can inject a script via the URL, potentially leading to XSS in the browser. The vulnerability only affects certain custom SSR/dev configurations, not plain `vite dev`. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-49293.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet