Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2022-21169
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.001
EPSS Ranking
24.8%
CVSS Severity
CVSS v3 Score
7.3
References
https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39a
https://github.com/AhmedAdelFahim/express-xss-sanitizer/issues/4
https://runkit.com/embed/w306l6zfm7tu
https://security.snyk.io/vuln/SNYK-JS-EXPRESSXSSSANITIZER-3027443
https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/3bf8aaaf4dbb1c209dcb8d87a82711a54c1ab39a
https://github.com/AhmedAdelFahim/express-xss-sanitizer/issues/4
https://runkit.com/embed/w306l6zfm7tu
https://security.snyk.io/vuln/SNYK-JS-EXPRESSXSSSANITIZER-3027443
Products affected by CVE-2022-21169
Express Xss Sanitizer Project
»
Express Xss Sanitizer
»
Version:
1.0.0
cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:1.0.0
Express Xss Sanitizer Project
»
Express Xss Sanitizer
»
Version:
1.0.1
cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:1.0.1
Express Xss Sanitizer Project
»
Express Xss Sanitizer
»
Version:
1.0.2
cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:1.0.2
Express Xss Sanitizer Project
»
Express Xss Sanitizer
»
Version:
1.1.0
cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:1.1.0
Express Xss Sanitizer Project
»
Express Xss Sanitizer
»
Version:
1.1.1
cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:1.1.1
Express Xss Sanitizer Project
»
Express Xss Sanitizer
»
Version:
1.1.2
cpe:2.3:a:express_xss_sanitizer_project:express_xss_sanitizer:1.1.2
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved