OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.owasp.antisamy:antisamy(Maven) | 0 | 1.6.6 | N/A |
CVSS Metrics