ApostropheCMS sanitize-html 2.7.1 for Node.js

CPE Details

ApostropheCMS sanitize-html 2.7.1 for Node.js
2.7.1
2022-10-20
09h40 +00:00
2022-10-20
15h44 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apostrophecms:sanitize-html:2.7.1:*:*:*:*:node.js:*:*

Informations

Vendor

apostrophecms

Product

sanitize-html

Version

2.7.1

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-21501 2024-02-24 05h00 +00:00 Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
5.3
Medium