Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
Software | From | Fixed in |
---|---|---|
pixel-apes_group / safehtml | 1.3.0 | 1.3.0.x |