ZeroHour

CVE-2023-3978

CVSS 3.1
6.1 medium
EPSS
<1%p56
Published
()
Modified
Description

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

Vendors
golang
Products
networking
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.