VDB
Sign up
MEDIUM6.1

GHSA-8j9v-h2vp-2hhv

XSS in HtmlSanitizer

Quick fix

GHSA-8j9v-h2vp-2hhv — HtmlSanitizer: upgrade to the fixed version with the command below.

dotnet add package HtmlSanitizer --version 5.0.372

Details

### Impact

If you have explicitly allowed the `<style>` tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the `<style>` tag so there is no risk if you have not explicitly allowed the `<style>` tag.

### Patches

The problem has been fixed in version 5.0.372.

### Workarounds

Remove the `<style>` tag from the set of allowed tags.

### For more information

If you have any questions or comments about this advisory open an issue in https://github.com/mganss/HtmlSanitizer

### Credits

This issue was discovered by Michal Bentkowski of Securitum.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/HtmlSanitizer
Introduced in: 0Fixed in: 5.0.372
Fixdotnet add package HtmlSanitizer --version 5.0.372

References