CVE-2022-21169
26.09.2022, 05:15
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
Vendor | Product | Version |
---|---|---|
express_xss_sanitizer_project | express_xss_sanitizer | 𝑥 < 1.1.3 |
𝑥
= Vulnerable software versions
References