Vulnerabilities/

Cross-Site Scripting in html-janitor

Severity:
Medium

Description

Versions of html-janitor prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).

This is exploitable if user-controlled data is passed into the modules clean() function.

Recommendation

Update the html-janitor package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
html-janitor
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing