Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-23899

Description

OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.

POC

Reference

No PoCs from references.

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/CodeIntelligenceTesting/java-example

- https://github.com/CodeIntelligenceTesting/java-example-old

- https://github.com/CodeIntelligenceTesting/jazzer

- https://github.com/TinkerBoard-Android/rockchip-android-external-jazzer-api

- https://github.com/msft-mirror-aosp/platform.external.jazzer-api