Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p68-m5qw-9g9w

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

HTML Purifier cross-site scripting (XSS) vulnerability

Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than CVE-2010-2479.

Пакеты

Наименование

ezyang/htmlpurifier

composer
Затронутые версииВерсия исправления

< 4.1.0

4.1.0

EPSS

Процентиль: 49%
0.00263
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than CVE-2010-2479.

nvd
больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than CVE-2010-2479.

debian
больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier b ...

EPSS

Процентиль: 49%
0.00263
Низкий

Дефекты

CWE-79