DOMSanitizer 是用于 PHP 7.3+ 的 DOM/SVG/MathML 内容安全库。在 1.0.15 版本之前, 方法负责拒绝 和 属性中存在危险的 URL 值。该实现的弱点在于:虽然对 方案进行了拒绝,但对 方案仅在 URL 值中包含字面量子字符串 时才进行拒绝(即使用正则表达式 进行匹配)。由于 载荷通常采用 Base64 编码,危险内容(如 标签、事件处理器等)在原始 URL 中不可见,因此无法通过该子字符串匹配检测出来。因此,类似 这样的 URL 即使在其解码后的载荷包含活跃标记(active
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rhukster | dom-sanitizer | < 1.0.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet