Overview : |
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari. |
Affected Product(s) : |
|
Vulnerability Details : |
||||
Solution : If you use DOMPurify, you should update it immediately to version 2.0.1 or newer. |