cbcvebase.
CVE-2021-35043
published 2021-07-19

CVE-2021-35043: OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
antisamy_projectantisamy< 1.6.41.6.4
debianlibowasp-antisamy-java< libowasp-antisamy-java 1.7.4-1 (forky)libowasp-antisamy-java 1.7.4-1 (forky)
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_managment2.3.0 – 2.4.0
oraclebanking_party_management
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform2.3.0 – 2.4.1
oracleinsurance_policy_administration
oracleinsurance_policy_administration
oracleinsurance_policy_administration
oracleinsurance_policy_administration
oracleinsurance_policy_administration
oraclemiddleware_common_libraries_and_tools
oraclemiddleware_common_libraries_and_tools
oracleretail_back_office
oracleretail_back_office
oracleretail_central_office
oracleretail_central_office
oracleretail_returns_management

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM