Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Authenticated DatoCMS Web Previews Plugin Iframe Injection
Vulnerability Description
Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabling the loading of arbitrary external resources or origins. This issue affects Web Previews < v1.0.31.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
DatoCMS 安全漏洞
Vulnerability Description
DatoCMS是DatoCMS开源的一个内容管理系统 DatoCMS v1.0.31之前版本存在安全漏洞,该漏洞源于身份验证的iframe注入,可能导致加载任意外部资源。
CVSS Information
N/A
Vulnerability Type
N/A