DOMPurify Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) Vulnerability - CVE-2024-48910 - Vulnerability Database
DOMPurify Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) Vulnerability - CVE-2024-48910
Critical
Reference:
CVE-2024-48910
Title:
DOMPurify Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) Vulnerability
Overview:
DOMPurify is a DOM-only super-fast uber-tolerant XSS sanitizer for HTML MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.