rails-html-sanitizer 库负责在 Rails 应用中清理 HTML 片段。从版本 1.0.3 到 1.7.1,Rails::HTML::PermitScrubber 仅在 SVG 元素使用 xlink:href 属性时才将 SVG 引用元素限制在 SVG_ALLOW_LOCAL_HREF 列表中,而实际上浏览器也支持使用普通的 href 属性。因此,如果应用自定义了允许标签并包含了 svg、use 或 feImage 元素,则可能允许外部引用。通过 use 元素引用同源外部 SVG 时,可能在清理
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rails | rails-html-sanitizer | >= 1.0.3, < 1.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rails | rails-html-sanitizer | >= 1.0.3, < 1.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet