VYPR

AntiSamy .NET

by Trustwave

Source repositories

CVEs (3)

  • CVE-2021-35043MedJul 19, 2021
    risk 0.40cvss 6.1epss 0.02

    OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

  • CVE-2022-29577MedApr 21, 2022
    risk 0.33cvss 6.1epss 0.01

    OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.

  • CVE-2022-28367MedApr 21, 2022
    risk 0.33cvss 6.1epss 0.01

    OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.