In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.owasp.antisamy:antisamy(Maven) | 0 | 1.5.5 | N/A |
CVSS Metrics