Mutation XSS Vulnerability in Mozilla Bleach Prior to 3.12
CVE-2020-6816
6.1MEDIUM
What is CVE-2020-6816?
A mutation Cross-Site Scripting (XSS) vulnerability exists in Mozilla Bleach versions prior to 3.12. This flaw arises when RCDATA and either SVG or MathML tags are whitelisted, while the 'strip' argument is set to false in the bleach.clean functionality. This vulnerability can potentially allow malicious scripts to be injected into web applications, making it crucial for developers using this library to update to the latest version.
Affected Version(s)
Mozilla Bleach <=3.11