Reflected cross-site scripting (XSS) In sanitize-html
Description
Cross-Site Scripting in sanitize-html
Affected versions of sanitize-html do not sanitize input recursively, which may allow an attacker to execute arbitrary Javascript.
Recommendation
Update to version 1.4.3 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.4.3 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5.