CVE-2024-47875
11.10.2024, 15:15
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
Vendor | Product | Version |
---|---|---|
cure53 | dompurify | 𝑥 < 2.5.0 |
cure53 | dompurify | 3.0.0 ≤ 𝑥 < 3.1.3 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cacti |
| ||||||||||||||
node-dompurify |
|

Ubuntu Releases
References