Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Pen-drive: pen-drive: stored xss via unescaped cluster data in html report
Vulnerability Description
A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Pen Drive 跨站脚本漏洞
Vulnerability Description
Pen Drive Pen Drive是Pen Drive组织的一款便携式存储设备。 Pen Drive存在跨站脚本漏洞,该漏洞源于将集群源数据呈现为HTML报告时缺乏适当的转义或清理,可能导致具有集群管理员权限的攻击者在集群对象(如ClusterVersion spec.channel)中注入存储型跨站脚本(XSS)有效载荷,并在打开生成的HTML报告的任何用户的浏览器中执行。
CVSS Information
N/A
Vulnerability Type
N/A