VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Apostrophecms
>
Sanitize Html
> 2.7.2
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2024-02-24
CVE-2024-21501
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies).
network
low complexity
apostrophecms
fedoraproject
5.3
5.3