Description
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Remediation
References
Related Vulnerabilities
WordPress Plugin Coming Soon Page & Maintenance Mode Cross-Site Scripting (1.8.1)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32028)
Magento Session Fixation Vulnerability (CVE-2019-8116)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-6385)