Laravel 是一个 Web 应用程序框架。在版本 12.69.0 和 13.30.0 之前,当 APP_DEBUG 设置为 true 时,Laravel 的异常调试页面会将攻击者可控的输入传递给一个配置了 allowHTML 为 true 的 Tippy.js 工具提示,从而在用户悬停在工具提示上时触发基于 DOM 的跨站脚本(XSS)漏洞。该问题已在版本 12.69.0 和 13.30.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet