lxml vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Jan 7, 2021
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Dec 3, 2020
Reviewed
Jan 7, 2021
Published to the GitHub Advisory Database
Jan 7, 2021
Last updated
Sep 30, 2024
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
References