SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-35043

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected).

MEDIUM 6.1EPSS 1.51%

Does this matter?

Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.

Description

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.51% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
antisamy project/antisamy · oracle/retail back office · oracle/retail central office · oracle/retail returns management · oracle/banking enterprise default management · oracle/banking enterprise default managment · oracle/banking party management · oracle/banking platform · oracle/insurance policy administration · oracle/middleware common libraries and tools · netapp/active iq unified manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.