sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
2023-02-24T06:15:11.317
2025-03-12T16:15:17.830
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | paypal | braintree\/sanitize-url | < 6.0.2 | Yes |