PT-2022-5409 · Owasp · Owasp Antisamy

Published

2022-04-10

·

Updated

2023-02-23

·

CVE-2022-29577

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OWASP AntiSamy versions prior to 1.6.7
Description The issue is related to the incorrect encoding of Cascading Style Sheets (CSS) content, allowing for HTML tag smuggling on STYLE content with crafted input. This can lead to cross-site scripting (XSS) attacks. The problem exists due to an incomplete fix for a previous issue.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of STYLE content to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-06725
CVE-2022-29577
GHSA-VP37-2F9P-3VR3

Affected Products

Owasp Antisamy