漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information about the rendering server and possibly creating an SSRF vector in the local network.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Vulnerability Title
pretix 跨站脚本漏洞
Vulnerability Description
pretix是德国pretix公司开源的一个票务系统。 pretix存在跨站脚本漏洞,该漏洞源于内容注入PDF渲染环境可包含HTML内容(包括img标签),如果这些图像的src属性指向URL,PDF渲染引擎将下载并显示该图像,从而泄露渲染服务器信息并可能在本地网络中形成SSRF向量。以下版本受到影响:2026.3.4之前版本、2026.4.4版本之前的2026.4.x版本和2026.5.2版本之前的2026.5.x版本。
CVSS Information
N/A
Vulnerability Type
N/A