Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING
Vulnerability Description
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Cure53 DOMPurify 跨站脚本漏洞
Vulnerability Description
Cure53 DOMPurify是Cure53公司开源的一款使用JavaScript编写的,用于HTML、MathML和SVG的DOM(文档对象模型)。 Cure53 DOMPurify 3.4.12之前版本存在跨站脚本漏洞,该漏洞源于CUSTOM_ELEMENT_HANDLING.tagNameCheck允许的自定义元素未执行afterSanitizeElements钩子,导致属性绕过应用程序安全策略,攻击者可以在自定义元素上保留敏感属性,随后将其重新注入innerHTML接收器,从而创建二阶跨站脚本小
CVSS Information
N/A
Vulnerability Type
N/A