CVE-2019-25155

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:39

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-07 03:09

Updated : 2024-11-21 04:39


NVD link : CVE-2019-25155

Mitre link : CVE-2019-25155

CVE.ORG link : CVE-2019-25155


JSON object : View

Products Affected

cure53

  • dompurify
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')