First published: Sat Dec 24 2016(Updated: )
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Antisamy Project Antisamy | <1.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.