Cure53 DOMPurify before 2.0.17... CVE-2020-26870

4.3 AV AC AU C I A
发布: 2020-10-07
修订: 2024-11-21

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.

0%
暂无可用Exp或PoC
当前有8条受影响产品信息