CVE-2021-35043
MEDIUMCVSS 6.1/10EPSS 1.51%
Last modified
CVE-2021-35043 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.. EPSS estimates a 1.51% chance of exploitation in the next 30 days.
Description
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Antisamy Project | Antisamy | < 1.6.4 |
| Oracle | Retail Back Office | 14.0 |
| Oracle | Retail Back Office | 14.1 |
| Oracle | Retail Central Office | 14.0 |
| Oracle | Retail Central Office | 14.1 |
| Oracle | Retail Returns Management | 14.0 |
| Oracle | Retail Returns Management | 14.1 |
| Oracle | Banking Enterprise Default Management | 2.6.2 |
| Oracle | Banking Enterprise Default Management | 2.7.0 |
| Oracle | Banking Enterprise Default Management | 2.7.1 |
| Oracle | Banking Enterprise Default Management | 2.10.0 |
| Oracle | Banking Enterprise Default Management | 2.12.0 |
| Oracle | Banking Enterprise Default Managment | >= 2.3.0, <= 2.4.0 |
| Oracle | Banking Party Management | 2.7.0 |
| Oracle | Banking Platform | >= 2.3.0, <= 2.4.1 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Banking Platform | 2.7.0 |
| Oracle | Banking Platform | 2.7.1 |
| Oracle | Insurance Policy Administration | 11.0.2 |
| Oracle | Insurance Policy Administration | 11.1.0 |
| Oracle | Insurance Policy Administration | 11.2.8 |
| Oracle | Insurance Policy Administration | 11.3.0 |
| Oracle | Insurance Policy Administration | 11.3.1 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.3.0 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.4.0 |
| Netapp | Active Iq Unified Manager | All versions |
References
- https://github.com/nahsra/antisamy/pull/87Patch, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://github.com/nahsra/antisamy/pull/87Patch, Third Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35043?
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
How severe is CVE-2021-35043?
CVE-2021-35043 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 1.51% probability of exploitation in the next 30 days.
How do I fix CVE-2021-35043?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-35036A cleartext storage of information vulnerability in the Zyxe…6.5
- CVE-2021-35037Jamf Pro before 10.30.1 allows for an unvalidated URL redire…6.1
- CVE-2021-35039kernel/module.c in the Linux kernel before 5.12.14 mishandle…7.8
- CVE-2021-3504A flaw was found in the hivex library in versions before 1.3…5.4
- CVE-2021-35041The blockchain node in FISCO-BCOS V2.7.2 may have a bug when…7.5
- CVE-2021-35042Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows Que…9.8
- CVE-2021-35045Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.O…6.1
- CVE-2021-35046A session fixation vulnerability was discovered in Ice Hrm 2…6.1
- CVE-2021-35047Vulnerability in the CommandPost, Collector, and Sensor comp…8.8
- CVE-2021-35048Vulnerability in Fidelis Network and Deception CommandPost e…9.8
- CVE-2021-35049Vulnerability in Fidelis Network and Deception CommandPost e…8.8
- CVE-2021-3505A flaw was found in libtpms in versions before 0.8.0. The TP…5.5
Are you affected by CVE-2021-35043?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
