Description
Versions of html-janitor prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).
This is exploitable if user-controlled data is passed into the modules clean() function.
Recommendation
Update the html-janitor package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.3
- Patched version(s): 2.0.3
References
Related Issues
- Cross-Site Scripting in sanitize-html - CVE-2017-16017
- Cross-Site Scripting in sanitize-html (GHSA-xc6g-ggrc-qq4r) - CVE-2017-16016
- Cross-Site Scripting in i18next (GHSA-cmh5-qc8w-xvcq) - CVE-2017-16010
- Cross-Site Scripting in i18next - CVE-2017-16008
- Tags:
- npm
- html-janitor
Anything's wrong? Let us know Last updated on September 12, 2023