i18next-http-backend 是 i18next 的后端层,用于在 Node.js、浏览器和 Deno 环境中加载翻译资源。在版本 4.0.2 之前,如果攻击者控制的 (语言)或 (命名空间)值被插入到自定义的 或 中,且该路径以 或 开头,则基于冒号(: // /locales/{{lng}}/{{ns}}.json`,也不影响包含前导路径或明确指定源地址的模板,因为在这类情况下,占位符并未位于 URL 的结构起始位置。 此问题已在版本 4.0.2 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| i18next | i18next-http-backend | < 4.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet