First published: Mon Sep 25 2017(Updated: )
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Antisamy Project Antisamy | <1.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.