CVE-2020-26293
—CVSS 3.1
6.1 medium
EPSS
<1%p61
Published
()
Modified
Description
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the ` ` tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the ` ` tag so there is no risk if you have not explicitly allowed the ` ` tag. The problem has been fixed in version 5.0.372.
- Vendors
- htmlsanitizer project
- Products
- htmlsanitizer
- Weakness
- CWE-74, CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.