DOMpurify has a nesting-based mXSS
Description
Published by the National Vulnerability Database
Oct 11, 2024
Published to the GitHub Advisory Database
Oct 11, 2024
Reviewed
Oct 11, 2024
Last updated
Oct 11, 2024
DOMpurify was vulnerable to nesting-based mXSS
fixed by 0ef5e537 (2.x) and
merge 943
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under test
References