An XSS vulnerability exists in python-lxml's clean module versions prior to 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
lxml lxml |
||
debian debian linux 9.0 |
||
debian debian linux 10.0 |
||
fedoraproject fedora 33 |
||
fedoraproject fedora 34 |
||
netapp snapcenter - |
||
oracle zfs storage appliance kit 8.8 |