CVE-2021-23899
13.01.2021, 16:15
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.Enginsight
Vendor | Product | Version |
---|---|---|
owasp | json-sanitizer | 𝑥 < 1.2.2 |
𝑥
= Vulnerable software versions
References