6.1
CVSSv3

CVE-2018-19787

Published: 02/12/2018 Updated: 26/11/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in lxml prior to 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote malicious user to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lxml lxml

debian debian linux 8.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 12.04

Vendor Advisories

lxml could allow cross-site scripting (XSS) attacks ...
lxml could allow cross-site scripting (XSS) attacks ...