在 team-alembic AshAuthentication 中存在一种“网页生成过程中对输入处理不当”(XSS)漏洞,允许通过确认表单和魔法链接(magic link)交互表单实现反射型跨站脚本攻击。 当策略配置中 设置为 时,AshAuthentication 会提供一个中间 HTML 页面,要求用户通过提交表单来确认操作。这两个页面都会将一个请求参数直接嵌入到隐藏输入框的 属性中,且未进行 HTML 转义: 会插值 参数,而 会插值魔法链接令牌(magic link token)参数。这些模板使用 编译,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| team-alembic | ash_authentication | 4.8.0< 4.14.2 |
affected |
5.0.0-rc.0< 5.0.0-rc.13 |
affected | ||
fe0b4558dbe852fee5d81a460a8355577618a8c8< * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| team-alembic | ash_authentication | 4.8.0 ~ 4.14.2 |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication | fe0b4558dbe852fee5d81a460a8355577618a8c8 ~ * |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet