Files
CVEs-PoC/2021/CVE-2021-23899.md
T
2025-09-29 21:09:30 +02:00

23 lines
971 B
Markdown

### [CVE-2021-23899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23899)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CodeIntelligenceTesting/java-example
- https://github.com/CodeIntelligenceTesting/java-example-old
- https://github.com/CodeIntelligenceTesting/jazzer
- https://github.com/TinkerBoard-Android/rockchip-android-external-jazzer-api
- https://github.com/msft-mirror-aosp/platform.external.jazzer-api