Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-5g2h-9x5v-5h3x: phoenix_html allows Cross-site Scripting in HEEx class attributes

tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.

ghsa
#xss#git

phoenix_html allows Cross-site Scripting in HEEx class attributes

Moderate severity GitHub Reviewed Published Jan 10, 2023 • Updated Jan 10, 2023

Related news

CVE-2021-46871: GHSA-j3gg-r6gp-95q2 - GitHub Advisory Database

tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.

ghsa: Latest News

GHSA-mqf3-qpc3-g26q: Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message