CVE-2021-23980
CVE-2021-23980
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Feb 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Mozilla · Mozilla BleachWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →