CVE-2021-28957

Summary: 
lxml 4.6.2 allows XSS. It places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.
Published: 
Sunday, March 21, 2021 - 05:15
cvss: 
5.0