漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Astro: Reflected XSS via unescaped slot name
Vulnerability Description
Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This vulnerability is fixed in 6.3.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Vulnerability Title
Astro 跨站脚本漏洞
Vulnerability Description
Astro是Astro团队开源的一个内容驱动网站的 web 框架。 Astro 6.3.3之前版本存在跨站脚本漏洞,该漏洞源于当组件使用client:*指令时,Astro将命名槽内容插入data-astro-template属性且未对槽名称进行HTML转义,可能允许攻击者突破属性环境并注入任意HTML,导致服务端渲染期间的反射型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A