Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Coolify has Stored XSS in Project Name
Vulnerability Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g., member role) can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator later attempts to delete the project or its associated resource, the payload automatically executes in the admin’s browser context. Version 4.0.0-beta.420.7 contains a patch for the issue.
CVSS Information
N/A
Vulnerability Type
对输出编码和转义不恰当
Vulnerability Title
Coolify 安全漏洞
Vulnerability Description
Coolify是coolLabs开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 Coolify v4.0.0-beta.420.6及之前版本存在安全漏洞,该漏洞源于项目创建流程中存在存储型跨站脚本,可能导致管理员浏览器环境中执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A