sanitize-html是Apostrophe Technologies开源的一个库。清理用户提交的 HTML,在每个元素的基础上保留列入白名单的元素和列入白名单的属性。 sanitize-html 2.7.1之前版本存在安全漏洞,该漏洞源于HTML注释删除的全局正则表达式替换逻辑不安全,存在正则表达式拒绝服务(ReDoS)的漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | sanitize-html | unspecified ~ 2.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25857 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25646 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-36565 | WampServer 安全漏洞 | |
| CVE-2022-36749 | RPi-Jukebox-RFID 操作系统命令注入漏洞 | |
| CVE-2022-36748 | PicUploader 跨站脚本漏洞 | |
| CVE-2022-36747 | Razor 跨站脚本漏洞 | |
| CVE-2022-36746 | LibreNMS 跨站脚本漏洞 | |
| CVE-2022-36745 | LibreNMS 跨站脚本漏洞 | |
| CVE-2022-36657 | Library Management System 跨站脚本漏洞 | |
| CVE-2022-36735 | Library Management System SQL注入漏洞 | |
| CVE-2022-36734 | Library Management System SQL注入漏洞 | |
| CVE-2022-36733 | Library Management System SQL注入漏洞 | |
| CVE-2022-36732 | Library Management System SQL注入漏洞 | |
| CVE-2022-36731 | Library Management System SQL注入漏洞 | |
| CVE-2022-36730 | Library Management System SQL注入漏洞 | |
| CVE-2022-37173 | Gvim 安全漏洞 | |
| CVE-2022-37172 | MSYS2 安全漏洞 | |
| CVE-2021-46837 | Asterisk 代码问题漏洞 | |
| CVE-2022-36564 | Perl 安全漏洞 | |
| CVE-2022-36563 | Rubyinstaller2 安全漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet