CVE-2018-7753

Source
https://cve.org/CVERecord?id=CVE-2018-7753
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-7753.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-7753
Aliases
Downstream
Related
Published
2018-03-07T23:29:00.273Z
Modified
2026-05-17T11:54:05.585064364Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

References

Affected packages