CVE-2019-25155

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*

History

14 Nov 2023, 18:49

Type Values Removed Values Added
CPE cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://github.com/cure53/DOMPurify/compare/1.0.10...1.0.11 - () https://github.com/cure53/DOMPurify/compare/1.0.10...1.0.11 - Patch
References () https://github.com/cure53/DOMPurify/pull/337/files - () https://github.com/cure53/DOMPurify/pull/337/files - Patch
First Time Cure53 dompurify
Cure53
CWE CWE-601

07 Nov 2023, 12:14

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-07 03:09

Updated : 2023-12-10 15:14


NVD link : CVE-2019-25155

Mitre link : CVE-2019-25155

CVE.ORG link : CVE-2019-25155


JSON object : View

Products Affected

cure53

  • dompurify
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')