
Cloud Vulnerability DB
A community-led vulnerabilities database
DOMPurify versions prior to 2.2.3 were vulnerable to Cross-site Scripting (XSS) due to issues with nested headlines. The vulnerability was published on January 11, 2023, and affected all versions below 2.2.3 (GitHub Advisory).
The vulnerability stems from an mXSS (Mutation-based XSS) issue reported by PewGrand. The issue was discovered on June 8, 2022, and received a CVSS score of 6.5 (medium severity). The vulnerability is tracked as CWE-79 and primarily affects the DOM-based sanitization functionality of the library (Snyk Advisory).
When exploited, this vulnerability could lead to Cross-site Scripting attacks, potentially allowing attackers to steal cookies, hijack user sessions, expose sensitive information, enable access to privileged services and functionality, and deliver malware (Snyk Advisory).
The vulnerability was patched in DOMPurify version 2.2.3. The recommended mitigation is to upgrade to version 2.2.3 or higher (GitHub Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."