CVE-2023-51652

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 2, 2024
Updated: Jan 8, 2024
CWE ID 79

Summary

CVE-2023-51652 is a new cross-site scripting (XSS) vulnerability affecting OWASP AntiSamy .NET before version 1.2.0. This issue arises due to flawed parsing of HTML in the library, which can result in executable code in comment tags when the `preserveComments` directive is enabled and certain tags are allowed. This can lead to mXSS attacks. To mitigate this risk, users can edit the policy file to remove the `preserveComments` directive or set it to false, as well as remove the `noscript` tag. However, these workarounds do not address the root cause of the vulnerability, and it is strongly recommended to upgrade to a fixed version of AntiSamy as soon as possible. The vulnerability exists in the library or its parser dependency, HtmlAgilityPack, and could potentially impact configurations that may change in the future.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-51652 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions