Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-28957
HistoryMar 21, 2021 - 5:15 a.m.

Cross site scripting

2021-03-2105:15:00
PRIOn knowledge base
www.prio-n.com
7

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.7%

An XSS vulnerability was discovered in python-lxml’s clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.