Cross-site Scripting in OWASP AntiSamy
Moderate severity
GitHub Reviewed
Published
Aug 2, 2021
to the GitHub Advisory Database
•
Updated May 15, 2024
Package
Affected versions
>= 1.5.7, < 1.6.4
Patched versions
1.6.4
Description
Published by the National Vulnerability Database
Jul 19, 2021
Reviewed
Jul 19, 2021
Published to the GitHub Advisory Database
Aug 2, 2021
Last updated
May 15, 2024
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
References