← Back

CVE-2022-29577

nvd nist
Published: Apr 21, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.

Affected (6)

Antisamy
2 products
Enterprise Manager Base Platform
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.6.7
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 13.4.0.0
Version 13.5.0.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0

References (6)

Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.