CVE-2021-35043
—CVSS 3.1
6.1 medium
EPSS
2%p73
Published
()
Modified
Description
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
- Vendors
- antisamy projectoraclenetapp
- Products
- antisamy, retail back office, retail central office, retail returns management, banking enterprise default management, banking enterprise default managment, banking party management, banking platform, insurance policy administration, middleware common libraries and tools, active iq unified manager
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.