Lucene search

K
cvelistMitreCVELIST:CVE-2021-35043
HistoryJul 19, 2021 - 2:53 p.m.

CVE-2021-35043

2021-07-1914:53:09
mitre
www.cve.org
5
owasp
antisamy
xss
html
attributes
serializer

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

40.3%

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

40.3%