Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29301
HistoryFeb 09, 2021 - 2:31 a.m.

Hostname Validation Bypass

2021-02-0902:31:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
hostname validation
bypass
sanitize-html
url parser
idna attack
internationalized domain name

EPSS

0.001

Percentile

49.3%

sanitize-html is vulnerable to hostname validation bypass. The package does not properly validate the iframe hostname in URL parser, allowing an IDNA (Internationalized Domain Name) iframe attack.

EPSS

0.001

Percentile

49.3%