Loading HuntDB...

CVE-2017-16017

UNKNOWN
Published 2018-06-04T19:00:00Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2017-16017. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

Cross-Site Scripting in sanitize-html

GHSA-wg96-3933-j2w5

Advisory Details

Affected versions of `sanitize-html` are vulnerable to cross-site scripting. ## Proof of Concept: `<IMG SRC= onmouseover="alert('XSS');">` produces the following: `<img src="onmouseover="alert('XSS');"" />` This is definitely invalid HTML, but would suggest that it's being interpreted incorrectly by the parser. ## Recommendation Update to version 1.2.3 or later.

Affected Packages

npm sanitize-html
ECOSYSTEM: ≥0 <1.2.3

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: November 9, 2018, Modified: September 8, 2023

References

Published: 2018-06-04T19:00:00Z
Last Modified: 2024-09-17T01:40:49.487Z
Copied to clipboard!