Description
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
Remediation
References
https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39a
https://github.com/AhmedAdelFahim/express-xss-sanitizer/issues/4
https://runkit.com/embed/w306l6zfm7tu
https://security.snyk.io/vuln/SNYK-JS-EXPRESSXSSSANITIZER-3027443
Related Vulnerabilities
CVE-2018-3720 Vulnerability in npm package assign-deep
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2021-23558 Vulnerability in npm package bmoor
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master