CVE-2024-21485: Dash Framework – Cross-site Scripting

CVE-2024-21485: Dash Framework - Cross-site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2024-21485: Dash Framework – Cross-site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-21485: Dash Framework – Cross-site Scripting

漏洞描述

Dash framework versions before 2.15.0 are vulnerable to Cross-site Scripting (xss) via href attribute in anchor tags. This template tests for javascript:alert payload injection.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享