GHSA-wg96-3933-j2w5
Dashboard / Vulnerabilities / GHSA-wg96-3933-j2w5
Summary: Cross-Site Scripting in sanitize-html
Details: Affected versions of `sanitize-html` are vulnerable to cross-site scripting. ## Proof of Concept: `<IMG SRC= onmouseover="alert('XSS');">` produces the following: `<img src="onmouseover="alert('XSS');"" />` This is definitely invalid HTML, but would suggest that it's being interpreted incorrectly by the parser. ## Recommendation Update to version 1.2.3 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16017, https://github.com/punkave/sanitize-html/issues/19, https://github.com/punkave/sanitize-html/pull/20, https://github.com/advisories/GHSA-wg96-3933-j2w5, https://www.npmjs.com/advisories/155
Affected packages
Package
Name: sanitize-html
Purl: pkg:npm/sanitize-html
Affected ranges
Type: SEMVER
Events:
