Логотип exploitDog
bind:CVE-2023-43643
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-43643

Количество 5

Количество 5

ubuntu логотип

CVE-2023-43643

больше 2 лет назад

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-43643

больше 2 лет назад

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-43643

больше 2 лет назад

AntiSamy is a library for performing fast, configurable cleansing of H ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pcf2-gh6g-h5r2

больше 2 лет назад

mXSS in AntiSamy

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2024-00589

около 2 лет назад

Уязвимость компонента Centralized Thirdparty Jars (AntiSamy) сервера приложений Oracle WebLogic Server программной платформы Oracle Fusion Middleware, позволяющая нарушителю провести атаку межсайтового скриптинга

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-43643

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-43643

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-43643

AntiSamy is a library for performing fast, configurable cleansing of H ...

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-pcf2-gh6g-h5r2

mXSS in AntiSamy

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-00589

Уязвимость компонента Centralized Thirdparty Jars (AntiSamy) сервера приложений Oracle WebLogic Server программной платформы Oracle Fusion Middleware, позволяющая нарушителю провести атаку межсайтового скриптинга

CVSS3: 6.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу