Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-28957 Details

Description

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://bugs.launchpad.net/lxml/+bug/1888153 CVEExploitIssue TrackingThird Party Advisory
https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999 CVEPatchThird Party Advisory
https://github.com/lxml/lxml/pull/316/commits/10ec1b4e9f93713513a3264ed6158af22492f270 CVEPatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/03/msg00031.html CVEMailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3C2R44VDUY7FJVMAVRZ2WY7XYL4SVN45/ CVE

see all 20 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')[email protected]
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CISA-ADP

Affected Products

ProductVersions
lxml lxml
< 4.6.3

CPE

  • cpe:2.3:a:lxml:lxml:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
9.0
10.0

CPE

  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
33
34

CPE

  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
netapp snapcenter
All versions

CPE

  • cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
oracle zfs storage appliance kit
8.8

CPE

  • cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

19 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-28957
NVD Published Date:
Mar 21, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]