CVE

CVE-2021-28957

CVE-2021-28957

lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.

Source: CVE-2021-28957

Exit mobile version