Lucene search

K
osvGoogleOSV:GHSA-HFJ4-96F7-6R5G
HistoryNov 09, 2018 - 5:49 p.m.

Cross-Site Scripting in html-janitor

2018-11-0917:49:11
Google
osv.dev
6

0.001 Low

EPSS

Percentile

41.5%

Versions of html-janitor prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).

This is exploitable if user-controlled data is passed into the modules clean() function.

Recommendation

No fix is currently available for this vulnerability. It is recommended to use an alternative module for HTML sanitization.

CPENameOperatorVersion
html-janitorlt2.0.3

0.001 Low

EPSS

Percentile

41.5%

Related for OSV:GHSA-HFJ4-96F7-6R5G