Reflected cross-site scripting (XSS) In dompurify
Description
Cross-site Scripting in dompurify Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 2.0.17 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.