Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgww-xf46-h92r

Опубликовано: 07 янв. 2021
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

lxml vulnerable to Cross-site Scripting

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

Пакеты

Наименование

lxml

pip
Затронутые версииВерсия исправления

< 4.6.2

4.6.2

EPSS

Процентиль: 76%
0.01026
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVSS3: 6.1
redhat
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVSS3: 6.1
nvd
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVSS3: 6.1
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 6.1
debian
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The ...

EPSS

Процентиль: 76%
0.01026
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79