CVE-2014-3146
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
MEDIUM · CVSS 6.1
EPSS 0.04268
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0