CVE-2025-8191: Swagger UI >=3.14.1 < 3.38.0 - DOM Based Cross-Site Scripting

CVE-2025-8191: Swagger UI >=3.14.1 < 3.38.0 - DOM Based Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2025-8191: Swagger UI >=3.14.1 < 3.38.0 - DOM Based Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-8191: Swagger UI >=3.14.1 < 3.38.0 – DOM Based Cross-Site Scripting

漏洞描述

Swagger UI versions 3.14.1 through 3.37.x are vulnerable to DOM-based Cross-Site Scripting (xss) attacks. The vulnerability occurs when processing malicious configuration URLs that contain XSS payloads in the Swagger specification. An attacker can craft a malicious configUrl parameter that, when processed by Swagger UI, executes arbitrary JavaScript code in the victim's browser context.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享