Lucene search

K
osvGoogleOSV:GHSA-57QW-CC2G-PV5P
HistoryMay 14, 2022 - 4:01 a.m.

lxml Cross-site Scripting Via Control Characters

2022-05-1404:01:59
Google
osv.dev
6

0.013 Low

EPSS

Percentile

86.0%

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

Rows per page:
1-10 of 521

References