CVE-2022-21169 Information

Description

The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute allowing the attacker to bypass xss sanitization.

Reference

https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39a https://github.com/AhmedAdelFahim/express-xss-sanitizer/issues/4 https://security.snyk.io/vuln/SNYK-JS-EXPRESSXSSSANITIZER-3027443 https://runkit.com/embed/w306l6zfm7tu

Share on: