CVE-2023-51652
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-51652 is a new cross-site scripting (XSS) vulnerability affecting OWASP AntiSamy .NET before version 1.2.0. This issue arises due to flawed parsing of HTML in the library, which can result in executable code in comment tags when the `preserveComments` directive is enabled and certain tags are allowed. This can lead to mXSS attacks. To mitigate this risk, users can edit the policy file to remove the `preserveComments` directive or set it to false, as well as remove the `noscript` tag. However, these workarounds do not address the root cause of the vulnerability, and it is strongly recommended to upgrade to a fixed version of AntiSamy as soon as possible. The vulnerability exists in the library or its parser dependency, HtmlAgilityPack, and could potentially impact configurations that may change in the future.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.