版本 1.7.0a0 至 1.9.3 的 在 OSC 8 超链接处理中存在跨站脚本(XSS)漏洞,原因是未能对 URL 目标进行校验或转义。能够控制 ANSI 文本输入的攻击者可以注入 协议,或通过截断 属性,从而在以转换后页面显示的环境中的任意脚本上下文中执行任意脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pycontribs | ansi2html | 1.7.0a0 ~ 1.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet