CVE-2021-26539

Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:node.js:*:*

Information

Published : 2021-02-08 09:15

Updated : 2022-04-26 08:24


NVD link : CVE-2021-26539

Mitre link : CVE-2021-26539


JSON object : View

Advertisement

dedicated server usa

Products Affected

apostrophecms

  • sanitize-html