cve/2021/CVE-2021-35043.md
2024-06-18 02:51:15 +02:00

865 B

CVE-2021-35043

Description

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

POC

Reference

Github

No PoCs found on GitHub currently.