Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
hbs vulnerable to XSS via registerAsyncHelper output-escaping bypass
Vulnerability Description
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder with the raw callback return value without escaping it, across the cached, uncached, and layout render paths. An application that passes attacker-influenced data, for example user-supplied content from a database, into an async helper callback can therefore have arbitrary HTML and JavaScript injected into the server-rendered page, resulting in stored or reflected cross-site scripting. Versions 2.1.0 through 4.2.1 are affected, and the issue is fixed in 4.3.0, which HTML-escapes async helper output. Applications that intentionally emit raw HTML from an async helper can opt in explicitly with hbs.SafeString. Users should upgrade to 4.3.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
pillarjs hbs 跨站脚本漏洞
Vulnerability Description
pillarjs hbs是pillarjs组织的一个服务器端模板渲染引擎。 pillarjs hbs 2.1.0版本至4.2.1版本存在跨站脚本漏洞,该漏洞源于registerAsyncHelper API绕过Handlebars的自动HTML转义,可能导致攻击者将任意HTML和JavaScript注入服务器渲染页面,造成存储型或反射型跨站脚本。
CVSS Information
N/A
Vulnerability Type
N/A