← Back to CVE List

CVE-2021-26539

Published: 2021-02-08T17:15Z
Last Modified: 2024-11-21T05:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt