CVE-2023-26491
rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters
6.1
MEDIUM
CVSS 3.1
EPSS 0.43%
描述
### Impact When the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code. Users who access the deliberately constructed URL are affected. ### Patches This vulnerability was fixed in version c910c4d28717fb860fbe064736641f379fab2c91. Please upgrade to this or a later version. ### Workarounds No.
如何修補 CVE-2023-26491
要修補 CVE-2023-26491,請將受影響套件升級到下列已修補版本。
- —升級至 1.0.0-master.c910c4d 或更新版本
CVE-2023-26491 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.0.0-master.c910c4d
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |