The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.
Link | Tags |
---|---|
http://www.osvdb.org/16612 | vdb entry |
http://pixel-apes.com/safehtml/feed | patch |
http://secunia.com/advisories/15371 | third party advisory |