Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability occurs in the webfonts API handling mechanism where font family names are not properly sanitized. An attacker can intercept fetch requests to the webfonts endpoint and inject malicious JavaScript payloads through font family names, resulting in session cookie theft, account hijacking, and unauthorized actions performed on behalf of authenticated users. The vulnerability can be exploited by injecting a fetch hook that returns controlled font data containing malicious scripts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SourceCodester AI Font Matcher 安全漏洞
Vulnerability Description
SourceCodester AI Font Matcher是SourceCodester开源的一个ai字体识别器。 SourceCodester AI Font Matcher存在安全漏洞,该漏洞源于字体家族名称清理不当,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A