cve/2020/CVE-2020-6816.md
2024-05-25 21:48:12 +02:00

784 B

CVE-2020-6816

Description

In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.

POC

Reference

Github