Related Vulnerabilities: CVE-2021-28957  

python-lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.

Severity Medium

Remote No

Type Insufficient validation

Description

python-lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.

AVG-1720 python-lxml 4.6.2-2 Medium Vulnerable

https://bugs.launchpad.net/lxml/+bug/1888153
https://github.com/lxml/lxml/pull/316