Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6000
HistoryMar 20, 2018 - 5:38 a.m.

Cross-site Scripting (XSS)

2018-03-2005:38:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.002 Low

EPSS

Percentile

59.1%

loofah is vulnerable to cross-site scripting (XSS) attacks. The vulnerability can occur under specific conditions when running on MRI or RBX and while using libxml2 >= 2.9.2. It exists as the scrub_attributes method in lib/loofah/html5/scrub.rb failed to sanitize some non-whitelisted attributes.