CVE-2021-35043

Publication date

2021-07-19 14:53:09

Family

mitre

State

PUBLISHED

Description

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.