CVE-2017-14735: XSS
Published Sep 25, 2017
·Updated
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.
Affected Software
1 affected component
AntiSamy project AntiSamy<1.5.7
Event History
Sep 25, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14735?
CVE-2017-14735 has been classified as a high severity vulnerability due to its potential to exploit XSS through HTML5 entities.
2
How do I fix CVE-2017-14735?
To fix CVE-2017-14735, update your AntiSamy library to version 1.5.7 or later.
3
What type of vulnerability is CVE-2017-14735?
CVE-2017-14735 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts via HTML5 entities.
4
What impact does CVE-2017-14735 have on web applications?
CVE-2017-14735 can allow attackers to perform unauthorized actions or steal confidential information from users interacting with a vulnerable web application.
5
Which software is affected by CVE-2017-14735?
CVE-2017-14735 affects all versions of the AntiSamy library before 1.5.7.