
CVE-2022-48345
https://notcve.org/view.php?id=CVE-2022-48345
24 Feb 2023 — sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities. • https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-23648 – Cross-site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-23648
16 Mar 2022 — The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. El paquete @braintree/sanitize-url versiones anteriores a 6.0.0 es vulnerable a un ataque de tipo Cross-site Scripting (XSS) debido a un saneo inapropiado en la función sanitizeUrl A flaw was found in sanitize-url due to improper sanitization in the sanitizeUrl function. This issue causes vulnerability to Cross-site Scripting in sanitize-url. Red Hat OpenShift C... • https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •