PT-2021-3745 · Owasp+1 · Owasp Antisamy+1

Published

2021-07-19

·

Updated

2022-10-29

·

CVE-2021-35043

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OWASP AntiSamy versions prior to 1.6.4
Description The issue allows for cross-site scripting (XSS) attacks via HTML attributes when using the HTML output serializer. This was demonstrated by a javascript: URL, where the colon character was replaced. The vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks, potentially allowing them to execute malicious scripts on a user's browser.
Recommendations For OWASP AntiSamy versions prior to 1.6.4, update to version 1.6.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of HTML attributes in the HTML output serializer to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-03998
CVE-2021-35043
GHSA-9C8W-JRW3-Q2C3

Affected Products

Debian
Owasp Antisamy