Cross-site scripting in Java HTML Sanitizer - #VU152247
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and modify web page content.
The vulnerability exists due to improper neutralization of input during web page generation in StylingPolicy URL handling when processing URLs in style attributes. A remote attacker can provide a URL containing quotes, backslashes, or control characters to disclose sensitive information and modify web page content.
User interaction is required.