First published: Thu Jan 23 2020(Updated: )
sanitize-html before 1.4.3 has XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apostrophecms Sanitize-html | <1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000237 is a vulnerability in sanitize-html before version 1.4.3 that allows for cross-site scripting (XSS) attacks.
CVE-2016-1000237 has a severity level of medium.
CVE-2016-1000237 affects Apostrophecms Sanitize-html before version 1.4.3.
To fix the CVE-2016-1000237 vulnerability, upgrade sanitize-html to version 1.4.3 or later.
The CWE ID for CVE-2016-1000237 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').