Vulnerabilities/

Bypassing Sanitization using DOM clobbering in html-janitor

Severity:
Medium

Description

All versions of html-janitor are vulnerable to cross-site scripting (XSS).

Arbitrary HTML can pass the sanitization process, which can be unexpected and dangerous (XSS) in case user-controlled input is passed to the clean function.”

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
html-janitor
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing