CVE Published: 16/02/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: mozilla |
Vendor: Mozilla |
Product: Mozilla Bleach Status : PUBLISHED
CVE-2021-23980 Description
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
CWE-ID: CWE Name: mutation XSS via allowed math or svg; p or br; and style, title, noscript, script, textarea, noframes, iframe, or xmp tags with strip_comments=False Source: Mozilla
Common Attack Pattern Enumeration and Classification (CAPEC)