Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
WebFeed HTML injection vulnerabilities
Vulnerability Description
WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFeed can lead to CSRF and UI spoofing attacks. A remote attacker can provide malicious RSS feeds and attract the victim user to visit it using WebFeed. The attacker can then inject malicious HTML into the extension page and fool the victim into sending out HTTP requests to arbitrary sites with the victim's credentials. Users are vulnerable to CSRF attacks when visiting malicious RSS feeds via WebFeed. Unwanted actions could be executed on the user's behalf on arbitrary websites. This issue has been addressed in release version 0.9.2. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
WebFeed 跨站脚本漏洞
Vulnerability Description
WebFeed是taoso个人开发者的一款轻量级的 RSS/Atom 阅读器。 WebFeed 0.9.2版本存在跨站脚本漏洞,该漏洞源于WebFeed中包含多个HTML注入漏洞可能导致跨站请求伪造和UI欺骗攻击。
CVSS Information
N/A
Vulnerability Type
N/A