Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-683w-6h9j-57wq

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

OWASP AntiSamy vulnerable to Cross-site Scripting

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

Пакеты

Наименование

org.owasp.antisamy:antisamy

maven
Затронутые версииВерсия исправления

< 1.5.5

1.5.5

EPSS

Процентиль: 67%
0.00539
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 9 лет назад

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

CVSS3: 6.1
nvd
около 9 лет назад

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

CVSS3: 6.1
debian
около 9 лет назад

In OWASP AntiSamy before 1.5.5, by submitting a specially crafted inpu ...

EPSS

Процентиль: 67%
0.00539
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79