Cross-Site Scripting in html-janitor
Moderate severity
GitHub Reviewed
Published
Nov 9, 2018
to the GitHub Advisory Database
•
Updated Sep 12, 2023
Description
Published to the GitHub Advisory Database
Nov 9, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2023
Versions of
html-janitor
prior to 2.0.2 (all current versions) are vulnerable to cross-site scripting (XSS).This is exploitable if user-controlled data is passed into the modules
clean()
function.Recommendation
No fix is currently available for this vulnerability. It is recommended to use an alternative module for HTML sanitization.
References