CVE-2016-10006

MEDIUM6.1EPSS 0.54%

OWASP AntiSamy vulnerable to Cross-site Scripting

發布日:2018/10/18修改日:2025/4/14
也稱為:GHSA-683w-6h9j-57wqDEBIAN-CVE-2016-10006

描述

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

參考連結(6)