Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29300
HistoryFeb 09, 2021 - 2:21 a.m.

Privilege Escalation

2021-02-0902:21:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
sanitize-html vulnerability
privilege escalation
bypass
iframe
hostname whitelist

EPSS

0.001

Percentile

49.3%

sanitize-html is vulnerable to privilege escalation. An attacker is able to bypass hostname whitelist for iframe element when the “allowIframeRelativeUrls” is set to true due to the hostnames set by the “allowedIframeHostnames” not properly validated.

EPSS

0.001

Percentile

49.3%