V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-28957
AST
Medium

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms argum…

CVSS
6.1
Medium
EPSS
0.04
p89
Published
2021-01-01
Updated
2021-01-01
Description

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

Tags · CWE
Pre-authXSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
LxmlLxmlLxmlLxmlLxmlLxmlLxmlLxmlLxmlLxmlPython-lxmlPython27Python38Python38-develPython39Python39-develRh-python38-babelRh-python38-babelRh-python38-pythonRh-python38-python
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.040 · p89
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
lxmlTracked
python-lxmlTracked
python27Tracked
python38Tracked
python38-develTracked
python39Tracked
python39-develTracked
rh-python38-babelTracked
rh-python38-babelTracked
rh-python38-pythonTracked
rh-python38-pythonTracked
Showing first 20 of 35
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities