CVE-2024-21501

MEDIUM

Apostrophecms Sanitize-html < 2.12.1 - Information Disclosure

Title source: rule
STIX 2.1

Description

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

Scores

CVSS v3 5.3
EPSS 0.0181
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-538
Status published
Products (4)
apostrophecms/sanitize-html < 2.12.1
fedoraproject/fedora 39
fedoraproject/fedora 40
npm/sanitize-html 0 - 2.12.1npm
Published Feb 24, 2024
Tracked Since Feb 18, 2026