Beveiligingsadvies

CVE-2014-3146

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2014-05-14 19:00:00
Laatst bijgewerkt 2025-12-17 21:03:02
Toegewezen door redhat
CVSS-score 6.1
Status PUBLISHED

Beschrijving

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.