First published: Thu Oct 31 2024(Updated: )
DOMPurify could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/dompurify | <2.4.2 | 2.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48910 is a high severity vulnerability that allows a remote authenticated attacker to execute arbitrary code due to prototype pollution.
To fix CVE-2024-48910, upgrade DOMPurify to version 2.4.2 or later.
CVE-2024-48910 affects applications that use the DOMPurify package versions prior to 2.4.2.
CVE-2024-48910 is a prototype pollution vulnerability that can lead to remote code execution.
Yes, CVE-2024-48910 can be exploited remotely by an authenticated attacker.