[KongchangAI]
Unverified50% confidenceFactExact time

允许用户提交包含 HTML 标记的富文本内容可能导致 XSS(跨站脚本攻击),恶意用户可注入 script 标签执行任意 JavaScript 代码

1
Sources
50%
Confidence
Long-term
Relevance
8/17/2026
First Seen

Sources

Related Claims

Cite This Claim

Stable URI
https://kongchang.com/claim/762742
API
curl https://kongchang.com/api/v1/knowledge/claims/762742
MCP
get_claim(id=762742)