First published: Fri Feb 24 2023(Updated: )
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paypal Braintree\/sanitize-url | <6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48345 is a vulnerability in sanitize-url (aka @braintree/sanitize-url) before version 6.0.2 that allows XSS (Cross-Site Scripting) attacks via HTML entities.
CVE-2022-48345 has a severity level of 6.1, which is classified as medium.
The sanitize-url vulnerability can be exploited by using HTML entities to inject malicious scripts into web applications.
Versions of sanitize-url (aka @braintree/sanitize-url) up to and excluding version 6.0.2 are affected by CVE-2022-48345.
To fix the sanitize-url vulnerability, update to version 6.0.2 or later of sanitize-url (aka @braintree/sanitize-url).