CVE-2017-16017: XSS

Published Jun 4, 2018
·
Updated

Affected versions of sanitize-html are vulnerable to cross-site scripting.

Proof of Concept:

<IMG SRC= onmouseover="alert('XSS');"> produces the following:

<img src="onmouseover="alert('XSS');"" /> This is definitely invalid HTML, but would suggest that it's being interpreted incorrectly by the parser.

Recommendation

Update to version 1.2.3 or later.

Other sources

sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.

Affected Software

2 affected componentsFixes available
npm/sanitize-html<1.2.3
1.2.3
Punkave Sanitize-html Node.js<=1.2.2

Event History

Jun 4, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Nov 9, 2018
Advisory Published
05:45 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-16017?

CVE-2017-16017 is classified as a high-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.

2

What versions of sanitize-html are affected by CVE-2017-16017?

CVE-2017-16017 affects versions of sanitize-html up to and including 1.2.2.

3

How can I fix CVE-2017-16017?

To fix CVE-2017-16017, upgrade sanitize-html to version 1.2.3 or later.

4

What type of vulnerability is CVE-2017-16017?

CVE-2017-16017 is a cross-site scripting (XSS) vulnerability found in the sanitize-html package.

5

How does CVE-2017-16017 impact web applications?

CVE-2017-16017 can allow attackers to execute arbitrary JavaScript in the context of the user's browser, compromising web application security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203