Incomplete blacklist vulnerability in the lxml.html.clean
module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html
function.
{ "nvd_published_at": "2014-05-14T19:55:00Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-08-04T20:12:48Z" }