CVE-2016-1000237: XSS
Published Jan 23, 2020
·Updated
sanitize-html before 1.4.3 has XSS.
Affected Software
1 affected component
apostrophecms Sanitize-html Node.js<1.4.3
Event History
Jan 23, 2020
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
Description
Frequently Asked Questions
1
What is CVE-2016-1000237?
CVE-2016-1000237 is a vulnerability in sanitize-html before version 1.4.3 that allows for cross-site scripting (XSS) attacks.
2
What severity level is assigned to CVE-2016-1000237?
CVE-2016-1000237 has a severity level of medium.
3
How does CVE-2016-1000237 affect Apostrophecms Sanitize-html?
CVE-2016-1000237 affects Apostrophecms Sanitize-html before version 1.4.3.
4
How can I fix the CVE-2016-1000237 vulnerability?
To fix the CVE-2016-1000237 vulnerability, upgrade sanitize-html to version 1.4.3 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2016-1000237?
The CWE ID for CVE-2016-1000237 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').