mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
899 B
899 B
CVE-2020-6802
Description
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
POC
Reference
- https://www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach
- https://www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach