Vulnerabilities > CVE-2020-27783

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE

Summary

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

Vulnerable Configurations

Part Description Count
Application
Lxml
111
Application
Redhat
1
Application
Netapp
1
Application
Oracle
2
OS
Redhat
1
OS
Debian
2
OS
Fedoraproject
2