First published: Tue Jan 26 2021(Updated: )
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apostrophecms Sanitize-html | <2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26540 is a vulnerability in Apostrophe Technologies sanitize-html before 2.3.2 that allows attackers to bypass hostname whitelisting for iframe elements.
The severity of CVE-2021-26540 is medium with a CVSS score of 5.3.
CVE-2021-26540 allows attackers to bypass hostname whitelist by setting hostnames through the "allowedIframeHostnames" option when "allowIframeRelativeUrls" is set to true.
Apostrophecms sanitize-html versions before 2.3.2 are affected by CVE-2021-26540.
To fix CVE-2021-26540, update Apostrophecms sanitize-html to version 2.3.2 or later.