漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CVAT has stored XSS via annotation guide assets
Vulnerability Description
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to an annotation guide, it labels them with a media type ( Content-Type ) that the attacker can influence, so instead of treating an uploaded file as plain data, the victim's browser can be told to treat it as an HTML page and run any JavaScript inside it. This issue has been fixed in version 2.67.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
cvat.ai CVAT 任意文件上传漏洞
Vulnerability Description
cvat-ai CVAT是cvat-ai组织开源的一款计算机视觉标注工具。 cvat.ai CVAT 2.5.0版本至2.66.0版本存在安全漏洞,该漏洞源于对注释指南附件的Content-Type处理不当,导致浏览器将上传文件作为HTML页面执行其中的JavaScript,容易受到跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A