Description
Versions of html-janitor prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).
This is exploitable if user-controlled data is passed into the modules clean() function.
Recommendation
Update the html-janitor package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.3
- Patched version(s): 2.0.3
References
Related Issues
- Cross-Site Scripting in sanitize-html - CVE-2017-16017
- Cross-Site Scripting in sanitize-html - sanitize-html - CVE-2017-16016
- Cross-Site Scripting in i18next - i18next - CVE-2017-16010
- Cross-Site Scripting in i18next - CVE-2017-16008
You might also like:
- Tags:
- npm
- html-janitor
Anything's wrong? Let us know Last updated on September 12, 2023


