ZeroHour

CVE-2021-23899

CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.

Vendors
owasp
Products
json-sanitizer
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.