Skip to main content

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-52595

Severity Medium
Score 6.1/10

Summary

The lxml_html_clean is a project for HTML cleaning functionalities copied from "lxml.html.clean". In versions prior to 0.4.0, the HTML Parser in "lxml" does not properly handle context-switching for special HTML tags such as "<svg>", "<math>" and "<noscript>". This behavior deviates from how web browsers parse and interpret such tags. Specifically, content in CSS comments is ignored by "lxml_html_clean" but may be interpreted differently by web browsers, enabling malicious scripts to bypass the cleaning process. This vulnerability could lead to Cross-Site Scripting (XSS) attacks, compromising the security of users relying on "lxml_html_clean" in the default configuration for sanitizing untrusted HTML content. Users employing the HTML cleaner in a security-sensitive context should upgrade to a patched version, which addresses this issue. As a temporary mitigation, users can configure "lxml_html_clean" with the following settings to prevent the exploitation of this vulnerability. Via "remove_tags", one may specify tags to remove - their content is moved to their parents' tags. Via "kill_tags", one may specify tags to be removed completely. Via "allow_tags", one may restrict the set of permissible tags, excluding context-switching tags like "<svg>", "<math>" and "<noscript>".

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • REQUIRED
  • NONE
  • LOW
  • NONE

CWE-79 - Cross Site Scripting

Cross-Site Scripting, commonly referred to as XSS, is the most dominant class of vulnerabilities. It allows an attacker to inject malicious code into a pregnable web application and victimize its users. The exploitation of such a weakness can cause severe issues such as account takeover, and sensitive data exfiltration. Because of the prevalence of XSS vulnerabilities and their high rate of exploitation, it has remained in the OWASP top 10 vulnerabilities for years.

Advisory Timeline

  • Published