This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerability, assuming an attacker can influence the value entered into the template. If the template is used to render user-generated content, this vulnerability may escalate to a persistent XSS vulnerability.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NCrowcpp Crow
APPCrowcpp< 0.3\+4
Powiązane podatności
Use-After-Free w Crow (CrowCpp) przy HTTP pipelining — możliwy RCE
Heap-based buffer overflow w Crow (RCE) przez funkcję qs_parse
HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data fr...
All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used t...
This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files fr...