PT-2011-4956 · Owasp · Owasp Html Sanitizer
Published
2011-11-17
·
Updated
2022-05-17
·
CVE-2011-4457
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OWASP HTML Sanitizer versions prior to 88
Description
The issue allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element when JavaScript is disabled.
Recommendations
For versions prior to 88, update to version 88 or later to resolve the issue.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Owasp Html Sanitizer