CVE-2023-38500Cross-site Scripting in Html Sanitizer

Severity
6.1MEDIUMNVD
CNA4.7
EPSS
0.3%
top 43.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25

Description

TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a `noscript` element was not encoded correctly. `noscript` is disabled in the default configuration, but might have been enabled in custom scenarios. This allows bypassing the cross-site s

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDtypo3/html_sanitizer1.0.01.5.1+1
Packagisttypo3/html-sanitizer1.0.01.5.1+1
CVEListV5typo3/html-sanitizer>= 1.0.0, < 1.5.1, >= 2.0.0, < 2.1.2+1

Patches

🔴Vulnerability Details

3
GHSA
By-passing Cross-Site Scripting Protection in HTML Sanitizer2023-07-25
CVEList
By-passing Cross-Site Scripting Protection in HTML Sanitizer2023-07-25
OSV
By-passing Cross-Site Scripting Protection in HTML Sanitizer2023-07-25
CVE-2023-38500 — Cross-site Scripting in Html Sanitizer | cvebase