在 rhukster/dom-sanitizer 1.0.15 及更早版本中发现了一个漏洞。受影响的是 SVG 净化组件中 文件里的 函数。该漏洞导致黑名单不完整,攻击者可远程利用此缺陷发起攻击。相关利用方法已公开披露,可能被实际使用。升级到 1.0.16 版本即可修复此问题。补丁提交哈希为 。建议升级受影响组件以消除风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rhukster | dom-sanitizer | 1.0.0 |
cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet