This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. T ...……
作者:菜鸟教程小白
|
时间:2022-6-22 22:03
|
阅读:8
|
回复:0