以下是对该漏洞描述的中文翻译: 漏洞描述: 在 Perl 模块 的 0.410002 版本之前的版本中, 方法在将字段属性渲染为 HTML 时,未对属性值进行转义处理。 任何包含字段或字段标签,且部分属性值来源于数据而非字面量的应用程序,都允许攻击者控制的文本出现在属性值中,从而可能覆盖字段属性,或在渲染后的页面中嵌入 JavaScript。 例如, 小部件通过 和 方法调用 方法,因此也受到影响。 --- 补充说明(便于理解): 核心问题:HTML 属性未转义(Unescaped HTML attributes)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 0.410002 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet