漏洞标题
通过HTML澄清剂绕过跨站点脚本保护
漏洞描述信息
绕过HTML净化器的跨站脚本保护
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
By-passing Cross-Site Scripting Protection in HTML Sanitizer
漏洞描述信息
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
TYPO3 安全漏洞
漏洞描述信息
TYPO3是瑞士TYPO3协会的一套免费开源的内容管理系统(框架)(CMS/CMF)。 TYPO3存在安全漏洞,该漏洞源于DOM处理指令无法正确处理,允许绕过typo3/html-sanitizer的跨站脚本机制。
CVSS信息
N/A
漏洞类别
其他