Vulnerability Details CVE-2023-44390
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `math` are in the list of allowed elements. In the case an application sanitizes user input with a vulnerable configuration, an attacker could bypass the sanitization and inject arbitrary HTML, including JavaScript code. Note that in the default configuration the vulnerability is not present. The vulnerability has been fixed in versions 8.0.723 and 8.1.722-beta (preview version).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.5%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-44390
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:-
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:2.0
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.0
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.76
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.79
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.91
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.93
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.1.98
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.2.100
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.2.103
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.2.105
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.122
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.125
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.126
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.127
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.128
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.129
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.130
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.131
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.132
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.134
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.140
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.142
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.143
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.144
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.145
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.146
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.147
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.3.148
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.4.152
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.4.156
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.5.167
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.5.168
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:3.5.169
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.179
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.180
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.181
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.182
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.183
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.185
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.186
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.187
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.188
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.189
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.190
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.191
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.192
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.193
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.195
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.197
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.198
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.199
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.200
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.201
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.202
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.203
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.204
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.205
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.207
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.209
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.210
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.211
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.212
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.217
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.219
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.220
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.222
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.224
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.228
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.229
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:4.0.230
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.214
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.215
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.216
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.218
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.233
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.234
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.236
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.237
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.239
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.240
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.242
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.244
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.245
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.246
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.248
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.249
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.250
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.251
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.257
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.258
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.260
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.261
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.263
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.264
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.266
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.267
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.269
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.270
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.272
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.274
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.275
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.277
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.278
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.280
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.281
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.283
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.284
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.287
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.288
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.290
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.291
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.292
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.293
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.294
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.296
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.297
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.298
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.303
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.304
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.305
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.307
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.308
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.310
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.311
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.313
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.314
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.316
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.317
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.319
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.320
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.322
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.323
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.325
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.326
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.328
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.329
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.331
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.332
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.341
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.342
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.343
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.344
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.346
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.347
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.349
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.350
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.352
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.353
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.354
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.355
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.358
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.359
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.361
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.363
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.364
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.365
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.366
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.367
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.368
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.369
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.371
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.372
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.373
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.375
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.376
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.377
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.379
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.380
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.382
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.383
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.385
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.386
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.388
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.389
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.391
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.392
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.395
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.398
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.400
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.401
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.403
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:5.0.404
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:6.0.409
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:6.0.423
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:6.0.430
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:6.0.437
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:6.0.441
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:6.0.453
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.0.470
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.0.473
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.1.475
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.1.488
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.1.509
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.1.512
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:7.1.542
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:8.0.601
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:8.0.645
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:8.0.692
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:8.0.718
-
cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:8.1.719