mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
863 B
863 B
CVE-2020-6816
Description
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
POC
Reference
- https://www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach
- https://www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach