ZeroHour

CVE-2021-35043

CVSS 3.1
6.1 medium
EPSS
2%p73
Published
()
Modified
Description

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.

Vendors
antisamy projectoraclenetapp
Products
antisamy, retail back office, retail central office, retail returns management, banking enterprise default management, banking enterprise default managment, banking party management, banking platform, insurance policy administration, middleware common libraries and tools, active iq unified manager
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.