CVE-2022-21169

7.3HIGH

The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.

公開日: 9/26/2022更新日: 5/21/2025

説明

The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.

AI分析AIによる分析

影響を受ける製品

express_xss_sanitizer_projectexpress_xss_sanitizer

参照