在 kagisearch smallweb(截至 commit 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf)中发现了一个安全漏洞。受影响的组件是 Query String Rendering 中 app/sw.py 文件里的 index 函数。通过操纵参数 可触发跨站脚本攻击(XSS),且该攻击可远程实施。 由于该产品采用滚动发布策略以实现持续交付,因此无法明确指出受影响的版本或修复版本的详细信息。修复补丁的标识为 00b68144e583f20a6b67e29cf01bc07
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kagisearch | smallweb | 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf |
cpe:2.3:a:kagisearch:smallweb:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet