PT-2023-29225 · Unknown · Sanitize-Html

Yaniv-Git

·

Publicado

2023-10-04

·

Atualizado

2023-10-12

·

CVE-2023-44390

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HtmlSanitizer versions prior to 8.0.723 HtmlSanitizer version 8.1.722-beta and earlier
Description The issue occurs in configurations where foreign content is allowed, specifically when svg or math are in the list of allowed elements. This allows an attacker to bypass sanitization and inject arbitrary HTML, including JavaScript code, when an application sanitizes user input with a vulnerable configuration. The default configuration is not affected.
Recommendations For HtmlSanitizer versions prior to 8.0.723, update to version 8.0.723 or later. For HtmlSanitizer version 8.1.722-beta and earlier, update to a version later than 8.1.722-beta. As a temporary workaround, consider disallowing foreign elements svg and math to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-44390
GHSA-43CP-6P3Q-2PC4

Produtos afetados

Sanitize-Html