CVE-2021-26539 Information
Jun 07, 2022
cve
Description
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the llowedIframeHostnames\ option.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Reference
https://github.com/apostrophecms/sanitize-html/pull/458 https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md#231-2021-01-22 https://advisory.checkmarx.net/advisory/CX-2021-4308
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
5.3
Share on: