PT-2018-6047 · Sanitize Html · Sanitize-Html
Publicado
2018-06-04
·
Atualizado
2019-10-09
·
CVE-2017-16017
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
sanitize-html versions 1.2.2 and below
Description:
The issue concerns a cross-site scripting vulnerability in the sanitize-html library, which is used for scrubbing HTML input for malicious values. This vulnerability can be exploited when the library incorrectly interprets certain HTML inputs, such as the example provided where an
<IMG> tag with an onmouseover attribute is not properly sanitized, resulting in the execution of JavaScript code. The estimated number of potentially affected devices worldwide is not specified.Recommendations:
For versions 1.2.2 and below, update to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the sanitize-html library until the update can be applied.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sanitize-Html