漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CKEditor Open Link plugin vulnerable to Cross-site Scripting
Vulnerability Description
ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin prior to 1.0.7 allowed a user to execute JavaScript code by abusing the link href attribute. The fix is available starting with version 1.0.7.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
CKEditor 跨站脚本漏洞
Vulnerability Description
CKEditor是Marek Lewandowski个人开发者的一套开源的、基于网页的文字编辑器。 CKEditor Open Link 1.0.7之前版本存在跨站脚本漏洞,该漏洞源于允许用户通过滥用链接href属性来执行JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A