Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
http://www.ubuntu.com/usn/USN-2217-1
http://www.openwall.com/lists/oss-security/2014/05/09/7
http://www.mandriva.com/security/advisories?name=MDVSA-2015:112
http://www.debian.org/security/2014/dsa-2941
http://secunia.com/advisories/59008
http://secunia.com/advisories/58744
http://secunia.com/advisories/58013
http://seclists.org/fulldisclosure/2014/Apr/210
http://lxml.de/3.3/changes-3.3.5.html
http://lists.opensuse.org/opensuse-updates/2014-05/msg00083.html
Published: 2014-05-14
Updated: 2025-04-12
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: Medium
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 5.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Severity: Medium
EPSS: 0.17998