9.8
CVE-2021-42576
- EPSS 0.45%
- Published 18.10.2021 15:15:07
- Last modified 21.11.2024 06:27:50
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Data is provided by the National Vulnerability Database (NVD)
Microco ≫ Bluemonday SwPlatformgo Version < 1.0.16
Python ≫ Pybluemonday Version < 0.0.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.626 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|