cve/2023/CVE-2023-24539.md
2024-05-25 21:48:12 +02:00

801 B

CVE-2023-24539

Description

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

POC

Reference

No PoCs from references.

Github