CVE-2024-47875

CVSS 3.1 Score 10 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 79

Summary

CVE-2024-47875 is a newly disclosed vulnerability affecting DOMPurify, a popular DOM-only XSS sanitizer used to protect against Cross-Site Scripting (XSS) attacks in HTML, MathML, and SVG. The flaw, labeled as mXSS (mass assignation XSS), is based on nesting and allows attackers to bypass the sanitization and inject malicious scripts. This vulnerability has been addressed in DOMPurify versions 2.5.0 and 3.1.3.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share