py3-lxml: missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)
lxml 4.6.2 allows XSS. It places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.
Fixed In Version:
py3-lxml 4.6.3
References:
Patch:
https://github.com/lxml/lxml/commit/2d01a1ba8984e0483ce6619b972832377f208a0d
Affected branches:
-
master (1beaaca1) -
3.13-stable