PT-2022-5409 · Owasp · Owasp Antisamy

CVE-2022-29577

·

Published

2022-04-10

·

Updated

2023-02-23

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OWASP AntiSamy versions prior to 1.6.7
Description The issue is related to the incorrect encoding of Cascading Style Sheets (CSS) content, allowing for HTML tag smuggling on STYLE content with crafted input. This can lead to cross-site scripting (XSS) attacks. The problem exists due to an incomplete fix for a previous issue.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of STYLE content to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06725
CVE-2022-29577
GHSA-VP37-2F9P-3VR3

Affected Products

Owasp Antisamy