6.1
CVSSv3

CVE-2022-21169

Published: 26/09/2022 Updated: 14/02/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The package express-xss-sanitizer prior to 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the malicious user to bypass xss sanitization.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

express xss sanitizer project express xss sanitizer