Astro - Reflected XSS via server islands feature
Astro 5.15.8 contains a reflected XSS caused by improper handling of server islands feature, letting remote attackers execute scripts, exploit requires use of server islands in the application. References: https://zhero-web-sec.github.io/research-and-things/unlocking-reflected-xss-in-the-astro-framework Remediation: Update to version 5.15.8 or later.
Used 3.4k times · domain, subdomain, ipv4