DOMPurify nesting-based mXSS
CVE-2024-47875

10CRITICAL

Key Information:

Vendor

Cure53

Status
Vendor
CVE Published:
11 October 2024

What is CVE-2024-47875?

DOMPurify, a widely-used sanitizer designed to clean HTML, MathML, and SVG content, has been found to have a vulnerability that allows for nesting-based malicious cross-site scripting (mXSS). This flaw enables attackers to exploit the sanitation process, potentially leading to the execution of unintended scripts in user browsers. To counter this risk, users are advised to upgrade to the latest secure versions, specifically 2.5.0 and 3.1.3, which include patches addressing this issue. Ensuring updates are applied will help maintain the integrity and security of web applications utilizing DOMPurify.

Affected Version(s)

DOMPurify < 2.5.0 < 2.5.0

DOMPurify < 3.1.3 < 3.1.3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.