Description
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
Remediation
References
http://www.securityfocus.com/bid/95101
http://www.securitytracker.com/id/1037532
https://github.com/nahsra/antisamy/issues/2
Related Vulnerabilities
CVE-2018-14042 Vulnerability in npm package bootstrap-sass
CVE-2018-1999002 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-2932 Vulnerability in maven package org.webjars.npm:mobiledoc-kit
CVE-2020-13697 Vulnerability in maven package org.nanohttpd:nanohttpd-nanolets
CVE-2020-15095 Vulnerability in maven package org.webjars:npm