Security Advisory

CVE-2020-27783

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-12-03 16:39:41
Last updated 2025-12-17 21:02:06
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.