Lucene search

K
osvGoogleOSV:CVE-2021-35043
HistoryJul 19, 2021 - 3:15 p.m.

CVE-2021-35043

2021-07-1915:15:07
Google
osv.dev
4
owasp
antisamy
vulnerability
html output
serializer

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

40.3%

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

40.3%