PT-2018-6047 · Sanitize Html · Sanitize-Html

Publicado

2018-06-04

·

Atualizado

2019-10-09

·

CVE-2017-16017

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: sanitize-html versions 1.2.2 and below
Description: The issue concerns a cross-site scripting vulnerability in the sanitize-html library, which is used for scrubbing HTML input for malicious values. This vulnerability can be exploited when the library incorrectly interprets certain HTML inputs, such as the example provided where an <IMG> tag with an onmouseover attribute is not properly sanitized, resulting in the execution of JavaScript code. The estimated number of potentially affected devices worldwide is not specified.
Recommendations: For versions 1.2.2 and below, update to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the sanitize-html library until the update can be applied.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16017
GHSA-WG96-3933-J2W5

Produtos afetados

Sanitize-Html