Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26540

Опубликовано: 08 фев. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\example.com".

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:node.js:*:*
Версия до 2.3.2 (исключая)

EPSS

Процентиль: 76%
0.01754
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
debian
больше 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly v ...

CVSS3: 5.3
github
больше 5 лет назад

Improper Input Validation in sanitize-html

EPSS

Процентиль: 76%
0.01754
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo