Описание
TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and the Roman characters. Prior to version 1.3.2, when using tuitse_html without quoting the input, there is a html injection vulnerability. Version 1.3.2 contains a patch for the issue. As a workaround, sanitize Taigi input with HTML quotation.
Ссылки
- Patch
- Issue TrackingPatch
- Vendor Advisory
- Patch
- Issue TrackingPatch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.2 (исключая)
cpe:2.3:a:ithuan:tuitse-tsusin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00495
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
около 2 лет назад
html injection vulnerability in the `tuitse_html` function.
EPSS
Процентиль: 65%
0.00495
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79