CVE-2021-35043
Last modified
CVE-2021-35043 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.. EPSS estimates a 1.51% chance of exploitation in the next 30 days.
Description
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Antisamy Project | Antisamy | < 1.6.4 |
| Oracle | Retail Back Office | 14.0 |
| Oracle | Retail Back Office | 14.1 |
| Oracle | Retail Central Office | 14.0 |
| Oracle | Retail Central Office | 14.1 |
| Oracle | Retail Returns Management | 14.0 |
| Oracle | Retail Returns Management | 14.1 |
| Oracle | Banking Enterprise Default Management | 2.6.2 |
| Oracle | Banking Enterprise Default Management | 2.7.0 |
| Oracle | Banking Enterprise Default Management | 2.7.1 |
| Oracle | Banking Enterprise Default Management | 2.10.0 |
| Oracle | Banking Enterprise Default Management | 2.12.0 |
| Oracle | Banking Enterprise Default Managment | >= 2.3.0, <= 2.4.0 |
| Oracle | Banking Party Management | 2.7.0 |
| Oracle | Banking Platform | >= 2.3.0, <= 2.4.1 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Banking Platform | 2.7.0 |
| Oracle | Banking Platform | 2.7.1 |
| Oracle | Insurance Policy Administration | 11.0.2 |
| Oracle | Insurance Policy Administration | 11.1.0 |
| Oracle | Insurance Policy Administration | 11.2.8 |
| Oracle | Insurance Policy Administration | 11.3.0 |
| Oracle | Insurance Policy Administration | 11.3.1 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.3.0 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.4.0 |
| Netapp | Active Iq Unified Manager | All versions |
References
- https://github.com/nahsra/antisamy/pull/87Patch, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://github.com/nahsra/antisamy/pull/87Patch, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35043?
How severe is CVE-2021-35043?
How do I fix CVE-2021-35043?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-35036A cleartext storage of information vulnerability in the Zyxe…6.5
- CVE-2021-35037Jamf Pro before 10.30.1 allows for an unvalidated URL redire…6.1
- CVE-2021-35039kernel/module.c in the Linux kernel before 5.12.14 mishandle…7.8
- CVE-2021-3504A flaw was found in the hivex library in versions before 1.3…5.4
- CVE-2021-35041The blockchain node in FISCO-BCOS V2.7.2 may have a bug when…7.5
- CVE-2021-35042Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows Que…9.8
- CVE-2021-35045Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.O…6.1
- CVE-2021-35046A session fixation vulnerability was discovered in Ice Hrm 2…6.1
- CVE-2021-35047Vulnerability in the CommandPost, Collector, and Sensor comp…8.8
- CVE-2021-35048Vulnerability in Fidelis Network and Deception CommandPost e…9.8
- CVE-2021-35049Vulnerability in Fidelis Network and Deception CommandPost e…8.8
- CVE-2021-3505A flaw was found in libtpms in versions before 0.8.0. The TP…5.5
Are you affected by CVE-2021-35043?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
