Zahir Uddin Ahmad pfp
Zahir Uddin Ahmad

@zuaxnull

CVE-2024-21501 I discovered a quirky vulnerability in sanitize-html When used on the backend with the style attribute allowed, it enables file system enumeration. Handy for uncovering a project's dependencies. https://security.snyk.io/vuln/SNYK-JS-SANITIZEHTML-6256334 #Security #Vulnerability #Javascript
0 reply
0 recast
0 reaction