CVE-2019-16728
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demo
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
MEDIUM · CVSS 6.1
EPSS 0.00962
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0