在版本 1.2.1 及以下的 项目中发现了一个漏洞。受影响的是该组件 中文件 的一个未知函数。对参数 的操作会导致跨站脚本攻击(XSS)。该攻击可以远程执行。项目方已通过 issue 报告提前获知此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quequnlong | shiyi-blog | 1.2.0 |
cpe:2.3:a:quequnlong:shiyi-blog:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet