Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjjq-c88q-qhr6

Опубликовано: 03 сент. 2020
Источник: github
Github: Прошло ревью

Описание

Cross-Site Scripting in dompurify

Versions of dompurify prior to 2.0.7 are vulnerable to Cross-Site Scripting (XSS). It is possible to bypass the package sanitization through Mutation XSS, which may allow an attacker to execute arbitrary JavaScript in a victim's browser.

Recommendation

Upgrade to version 2.0.7 or later.

Пакеты

Наименование

dompurify

npm
Затронутые версииВерсия исправления

< 2.0.7

2.0.7

Дефекты

CWE-79

Дефекты

CWE-79