PT-2023-31065 · Unknown · Domsanitizer

Rhukster

·

Publicado

2023-11-22

·

Atualizado

2023-11-28

·

CVE-2023-49146

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DOMSanitizer versions prior to 1.0.7
Description The issue arises from the mishandling of comments and the use of greedy regular expressions in SVG documents, leading to a potential XSS attack.
Recommendations For versions prior to 1.0.7, update to version 1.0.7 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49146
GHSA-2GHM-R75J-PJX2

Produtos afetados

Domsanitizer