ZeroHour

CVE-2017-16876

CVSS 3.0
6.1 medium
EPSS
2%p82
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

Vendors
mistune projectfedoraproject
Products
mistune, fedora
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.