mozilla bleach CVE-2018-7753 in Mozilla and Canonical Products
Published on March 7, 2018

product logo product logo
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

NVD


Products Associated with CVE-2018-7753

stack.watch emails you whenever new vulnerabilities are published in Mozilla Bleach or Canonical Ubuntu Linux. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.51%
Percentile
66.10%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.