Improper Policy Enforcement in OWASP Java HTML Sanitizer (before 20211018.1) for SELECT, STYLE, and OPTION Elements

Improper Policy Enforcement in OWASP Java HTML Sanitizer (before 20211018.1) for SELECT, STYLE, and OPTION Elements

CVE-2021-42575 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Learn more about our Web Application Penetration Testing UK.