CVE

CVE-2017-15612

CVE-2017-15612

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in javanscript:) or a crafted email address, related to the escape and autolink functions.

Source: CVE-2017-15612

Exit mobile version