MEDIUM · 6.1

CVE-2021-35043

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for...

Vulnerability Description

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Antisamy ProjectAntisamy< 1.6.4
OracleRetail Back Office14.0
OracleRetail Central Office14.0
OracleRetail Returns Management14.0
OracleBanking Enterprise Default Management2.6.2
OracleBanking Enterprise Default Managment>= 2.3.0, <= 2.4.0
OracleBanking Party Management2.7.0
OracleBanking Platform>= 2.3.0, <= 2.4.1
OracleInsurance Policy Administration11.0.2
OracleMiddleware Common Libraries And Tools12.2.1.3.0
NetappActive Iq Unified Manager-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-35043?

CVE-2021-35043 is a vulnerability with a CVSS score of 6.1 (MEDIUM). OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for...

How severe is CVE-2021-35043?

CVE-2021-35043 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-35043?

Check the references section above for vendor advisories and patch information. Affected products include: Antisamy Project Antisamy, Oracle Retail Back Office, Oracle Retail Central Office, Oracle Retail Returns Management, Oracle Banking Enterprise Default Management.