959 Star 5.1K Fork 1.6K

GVPsmallwei/Avue

 / 详情

avueUeditor插入视频存在XSS漏洞

Closed
Opened this issue  
2024-06-04 09:56

输入图片说明

使用avueUeditor组件,点击插入【视频】按钮,然后输入截图中内容后点击插入:会直接执行js脚本

输入图片说明

"avue-plugin-ueditor": "^0.2.0",

Comments (1)

tony created任务
tony changed description
tony changed description
tony changed description
Expand operation logs

富文本不维护了

smallwei changed issue state from 待办的 to 已关闭

Sign in to comment

Status
Assignees
Milestones
Pull Requests
Successfully merging a pull request will close this issue.
Branches
Planed to start   -   Planed to end
-
Top level
Priority
参与者(2)
632261 smallweigit 1588214431
JavaScript
1
https://gitee.com/smallweigit/avue.git
git@gitee.com:smallweigit/avue.git
smallweigit
avue
Avue

Search

344bd9b3 5694891 D2dac590 5694891