Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Caddy: stripHTML template function bypass
Vulnerability Description
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
对输出编码和转义不恰当
Vulnerability Title
caddyserver caddy 输出处理不当漏洞
Vulnerability Description
caddyserver caddy是caddyserver团队开源的一款Web服务器软件。 caddyserver caddy 2.11.4之前版本存在输出处理不当漏洞,该漏洞源于stripHTML模板函数无法可靠移除所有HTML标签,某些畸形HTML可绕过标签剥离逻辑,可能导致客户端跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A