PT-2023-29225 · Unknown · Sanitize-Html

Yaniv-Git

·

Published

2023-10-04

·

Updated

2023-10-12

·

CVE-2023-44390

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HtmlSanitizer versions prior to 8.0.723 HtmlSanitizer version 8.1.722-beta and earlier
Description The issue occurs in configurations where foreign content is allowed, specifically when svg or math are in the list of allowed elements. This allows an attacker to bypass sanitization and inject arbitrary HTML, including JavaScript code, when an application sanitizes user input with a vulnerable configuration. The default configuration is not affected.
Recommendations For HtmlSanitizer versions prior to 8.0.723, update to version 8.0.723 or later. For HtmlSanitizer version 8.1.722-beta and earlier, update to a version later than 8.1.722-beta. As a temporary workaround, consider disallowing foreign elements svg and math to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-44390
GHSA-43CP-6P3Q-2PC4

Affected Products

Sanitize-Html