Description
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.
Remediation
References
Related Vulnerabilities
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more Cross-Site Scripting (2.5.2.1)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-19499)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17670)
WordPress Plugin Email newsletter Cross-Site Scripting (20.13.6)