CVE-2022-28367
21.04.2022, 23:15
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
| Vendor | Product | Version |
|---|---|---|
| antisamy_project | antisamy | 𝑥 < 1.6.6 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases