Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
[qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Vulnerability Description
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Qwik 跨站请求伪造漏洞
Vulnerability Description
Qwik是Qwik Dev开源的一款微型Web框架。 Qwik 1.12.0之前版本存在跨站请求伪造漏洞,该漏洞源于正则表达式存在拼写错误,导致对某些Content-Type标头的解析不正确。
CVSS Information
N/A
Vulnerability Type
N/A