CVE-2018-7753

Publication date

2018-03-07 23:00:00

Family

mitre

State

PUBLISHED

Description

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values werent properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.