Логотип exploitDog
bind:CVE-2024-23635
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-23635

Количество 5

Количество 5

ubuntu логотип

CVE-2024-23635

около 2 лет назад

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. Patched in AntiSamy 1.7.5 and later.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-23635

около 2 лет назад

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. Patched in AntiSamy 1.7.5 and later.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-23635

около 2 лет назад

AntiSamy is a library for performing fast, configurable cleansing of H ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mrq-w8pv-5pvq

около 2 лет назад

Malicious input can provoke XSS when preserving comments

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2024-03300

около 2 лет назад

Уязвимость библиотеки для выполнения быстрой настраиваемой очистки HTML AntiSamy, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-23635

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. Patched in AntiSamy 1.7.5 and later.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-23635

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. Patched in AntiSamy 1.7.5 and later.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-23635

AntiSamy is a library for performing fast, configurable cleansing of H ...

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mrq-w8pv-5pvq

Malicious input can provoke XSS when preserving comments

CVSS3: 6.1
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-03300

Уязвимость библиотеки для выполнения быстрой настраиваемой очистки HTML AntiSamy, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 6.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу