Логотип exploitDog
bind:CVE-2021-26540
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-26540

Количество 4

Количество 4

redhat логотип

CVE-2021-26540

около 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-26540

около 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-26540

около 5 лет назад

Apostrophe Technologies sanitize-html before 2.3.2 does not properly v ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mjxr-4v3x-q3m4

почти 5 лет назад

Improper Input Validation in sanitize-html

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-26540

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-26540

Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-26540

Apostrophe Technologies sanitize-html before 2.3.2 does not properly v ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
github логотип
GHSA-mjxr-4v3x-q3m4

Improper Input Validation in sanitize-html

CVSS3: 5.3
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу