OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Antisamy Project
Subscribe
|
Antisamy
Subscribe
|
|
Netapp
Subscribe
|
Active Iq Unified Manager
Subscribe
|
|
Oracle
Subscribe
|
Banking Enterprise Default Management
Subscribe
Banking Enterprise Default Managment
Subscribe
Banking Party Management
Subscribe
Banking Platform
Subscribe
Insurance Policy Administration
Subscribe
Middleware Common Libraries And Tools
Subscribe
Retail Back Office
Subscribe
Retail Central Office
Subscribe
Retail Returns Management
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1654 | OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character. |
Github GHSA |
GHSA-9c8w-jrw3-q2c3 | Cross-site Scripting in OWASP AntiSamy |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:33:50.696Z
Reserved: 2021-06-18T00:00:00
Link: CVE-2021-35043
No data.
Status : Modified
Published: 2021-07-19T15:15:07.747
Modified: 2024-11-21T06:11:44.160
Link: CVE-2021-35043
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA