Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29778
HistoryMar 22, 2021 - 5:25 a.m.

Cross-site Scripting (XSS)

2021-03-2205:25:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
lxml
vulnerability
cross-site scripting
html action attribute

EPSS

0.002

Percentile

61.6%

lxml is vulnerable to cross-site scripting (XSS). An attacker is able to inject and execute arbitrary script via HTML action attribute into defs.link_attrs (in html/defs.py).