6.1
CVSSv3

CVE-2016-10006

Published: 24/12/2016 Updated: 14/11/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In OWASP AntiSamy prior to 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

antisamy project antisamy

Vendor Advisories

Debian Bug report logs - #1014981 libowasp-antisamy-java: CVE-2016-10006 CVE-2017-14735 CVE-2021-35043 Package: src:libowasp-antisamy-java; Maintainer for src:libowasp-antisamy-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 15 ...