Security Advisory

CVE-2021-26539

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-08 16:16:06
Last updated 2024-08-03 20:26:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.