CVE-2020-27783
MEDIUMlxml < 4.6.2 - Cross-Site Scripting via Clean Module Parser
Title source: llmDescription
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
References (8)
Core 8
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1901633
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2020/dsa-4810
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/12/msg00028.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMHVKRUT22LVWNL3TB7HPSDHJT74Q3JK/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JKG67GPGTV23KADT4D4GK4RMHSO4CIQL/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Exploit, Third Party Advisory x_refsource_misc
https://advisory.checkmarx.net/advisory/CX-2020-4286
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210521-0003/
Scores
CVSS v3
6.1
EPSS
0.0125
EPSS Percentile
79.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (11)
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
32
fedoraproject/fedora
33
lxml/lxml
1.2 - 4.6.2
netapp/snapcenter
oracle/communications_offline_mediation_controller
12.0.0.3.0
oracle/zfs_storage_appliance_kit
8.8
pypi/lxml
0 - 4.6.2PyPI
redhat/enterprise_linux
8.0
... and 1 more
Published
Dec 03, 2020
Tracked Since
Feb 18, 2026