ZeroHour

CVE-2016-10006

CVSS 3.1
6.1 medium
EPSS
2%p80
Published
()
Modified
Description

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

Vendors
antisamy project
Products
antisamy
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.