Description
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
Remediation
References
https://lists.debian.org/debian-lts-announce/2020/10/msg00029.html
https://research.securitum.com/dompurify-bypass-using-mxss/
Related Vulnerabilities
CVE-2021-46363 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2016-7103 Vulnerability in npm package jquery-ui
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:api-ldap-model
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.gce
CVE-2023-30524 Vulnerability in maven package org.jenkins-ci.plugins:reportportal