PT-2023-8390 · Antisamy+1 · Antisamy+1

Leen

·

Published

2023-10-09

·

Updated

2024-01-16

·

CVE-2023-43643

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions AntiSamy versions prior to 1.7.4
Description The issue is related to a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability, the preserveComments directive must be enabled in the policy file and certain tags must be allowed at the same time. This can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output.
Recommendations For versions prior to 1.7.4, update to AntiSamy 1.7.4 or later to resolve the issue. As a temporary workaround, manually edit the AntiSamy policy file by deleting the preserveComments directive or setting its value to false, if present. Additionally, consider adding a tag definition to remove the noscript tag under the <tagrules> node.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-00589
CVE-2023-43643
GHSA-PCF2-GH6G-H5R2

Affected Products

Antisamy
Debian