Lucene search

K
nodejs_bayotopNODEJS:576
HistoryApr 24, 2018 - 2:21 p.m.

Cross-Site Scripting

2018-04-2414:21:37
_bayotop
www.npmjs.com
13

0.001 Low

EPSS

Percentile

41.5%

Overview

Versions of html-janitor prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).

This is exploitable if user-controlled data is passed into the modules clean() function.

Recommendation

No fix is currently available for this vulnerability. It is recommended to use an alternative module for HTML sanitization.

References

CPENameOperatorVersion
html-janitorge0.0.0

0.001 Low

EPSS

Percentile

41.5%