HTML Injection Vulnerability in OWASP JSON Sanitizer
CVE-2021-23899
9.8CRITICAL
What is CVE-2021-23899?
The OWASP JSON Sanitizer prior to version 1.2.2 is vulnerable to an HTML injection flaw that allows an attacker to manipulate crafted input, potentially leading to the emission of unauthorized closing SCRIPT tags and CDATA section delimiters. This vulnerability permits the injection of arbitrary HTML or XML into embedding documents, posing significant risks to applications that rely on this sanitization mechanism.
