Vulnerability Report: GO-2022-0762
- CVE-2021-29272, GHSA-3x58-xr87-2fcj
- Affects: github.com/microcosm-cc/bluemonday
- Published: May 18, 2021
- Modified: May 20, 2024
An XSS injection was possible because the sanitization of the Cyrillic character i bypass a protection mechanism against user-inputted HTML elements such as the <script> tag.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.0.5
Aliases
References
- https://github.com/microcosm-cc/bluemonday/commit/524f142fe46e945b7dcd291d7805c4b7dcf75bee
- https://github.com/microcosm-cc/bluemonday/issues/111
- https://github.com/microcosm-cc/bluemonday/releases/tag/v1.0.5
- https://vuln.go.dev/ID/GO-2022-0762.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.