Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation
Vulnerability Description
Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted or multi-valued Content-Type headers. This issue has been patched in version 1.19.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Qwik 跨站请求伪造漏洞
Vulnerability Description
Qwik是Qwik Dev开源的一款微型Web框架。 Qwik 1.19.0之前版本存在跨站请求伪造漏洞,该漏洞源于服务器端请求处理程序对HTTP请求标头的解释不一致,可能导致远程攻击者使用特制或多值的Content-Type标头绕过表单提交CSRF保护。
CVSS Information
N/A
Vulnerability Type
N/A