OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) prior to 88, when JavaScript is disabled, allows user-assisted remote malicious users to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
owasp-java-html-sanitizer project owasp-java-html-sanitizer |
||
owasp-java-html-sanitizer project owasp-java-html-sanitizer 42 |
||
owasp-java-html-sanitizer project owasp-java-html-sanitizer 48 |
||
owasp-java-html-sanitizer project owasp-java-html-sanitizer 50 |
||
owasp-java-html-sanitizer project owasp-java-html-sanitizer 74 |