2 results (0.008 seconds)

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

24 Feb 2023 — sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities. • https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 1

16 Mar 2022 — The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. El paquete @braintree/sanitize-url versiones anteriores a 6.0.0 es vulnerable a un ataque de tipo Cross-site Scripting (XSS) debido a un saneo inapropiado en la función sanitizeUrl A flaw was found in sanitize-url due to improper sanitization in the sanitizeUrl function. This issue causes vulnerability to Cross-site Scripting in sanitize-url. Red Hat OpenShift C... • https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •