PT-2024-18917 · Unknown+1 · Sanitize-Html+1
Slonser
+1
·
Published
2024-02-23
·
Updated
2026-03-10
·
CVE-2024-21501
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
sanitize-html versions prior to 2.12.1
Description
The issue allows for Information Exposure when the style attribute is permitted on the backend, enabling an attacker to enumerate files in the system, including project dependencies. This could be exploited to gather details about the file system structure and dependencies of the targeted server.
Recommendations
For versions prior to 2.12.1, update to version 2.12.1 or later to resolve the issue. As a temporary workaround, consider disabling the style attribute when using sanitize-html on the backend to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Sanitize-Html