Количество 2
Количество 2
CVE-2022-21169
больше 3 лет назад
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
CVSS3: 7.3
EPSS: Низкий
GHSA-grjp-4jmr-mjcw
больше 3 лет назад
express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute
CVSS3: 6.1
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-21169 The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization. | CVSS3: 7.3 | 0% Низкий | больше 3 лет назад | |
GHSA-grjp-4jmr-mjcw express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20