Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
lxml‘clean_html’函数安全绕过漏洞
Vulnerability Description
lxml是一个使用Python语言编写的用于处理XML和HTML的库。 lxml 3.3.4及之前版本的lxml.html.clean模块中存在不完整黑名单漏洞,该漏洞源于程序没有正确过滤link scheme中的控制字符。远程攻击者可利用该漏洞实施跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A