CVE-2019-25155Open Redirect in Dompurify

CWE-601Open Redirect5 documents4 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 52.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 7
Latest updateNov 14

Description

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDcure53/dompurify< 1.0.11
npmcure53/dompurify< 1.0.11

Patches

🔴Vulnerability Details

4
GHSA
DOMPurify Open Redirect vulnerability2023-11-14
OSV
DOMPurify Open Redirect vulnerability2023-11-14
OSV
CVE-2019-25155: DOMPurify before 12023-11-07
CVEList
CVE-2019-25155: DOMPurify before 12023-10-31
CVE-2019-25155 — Open Redirect in Cure53 Dompurify | cvebase