First published: Wed Nov 22 2023(Updated: )
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getgrav Dom-sanitizer | <1.0.7 | |
composer/rhukster/dom-sanitizer | <1.0.7 | 1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for DOMSanitizer is CVE-2023-49146.
DOMSanitizer allows XSS attacks by mishandling comments and greedy regular expressions in SVG documents.
The affected version of DOMSanitizer is before 1.0.7.
To fix the DOMSanitizer vulnerability, update to version 1.0.7 or later.
The CWE ID for DOMSanitizer is CWE-79.