ZeroHour

CVE-2021-42576

PoC
CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Vendors
microcopython
Products
bluemonday, pybluemonday
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.