CVE-2021-35043

Related Vulnerabilities: CVE-2021-35043  

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

Description

The MITRE CVE dictionary describes this issue as:

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

Additional Information

  • Bugzilla 1985315: CVE-2021-35043 AntiSamy: XSS via HTML attributes
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • FAQ: Frequently asked questions about CVE-2021-35043