First published: Tue Oct 31 2023(Updated: )
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cure53 DOMPurify | <1.0.11 | |
npm/dompurify | <1.0.11 | 1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-25155.
The severity level of CVE-2019-25155 is medium with a CVSS score of 6.1.
DOMPurify before version 1.0.11 is affected by CVE-2019-25155.
CVE-2019-25155 allows reverse tabnabbing, which can lead to phishing attacks or the disclosure of sensitive information.
To fix CVE-2019-25155, upgrade DOMPurify to version 1.0.11 or later.