cve/2017/CVE-2017-16876.md
2024-05-26 14:27:05 +02:00

687 B

CVE-2017-16876

Description

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

POC

Reference

No PoCs from references.

Github