Description
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
Remediation
References
Related Vulnerabilities
WordPress Plugin AddToAny Share Buttons Host Header Injection (1.7.14)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0701)
MySQL CVE-2015-4771 Vulnerability (CVE-2015-4771)
Grafana Improper Input Validation Vulnerability (CVE-2022-39306)
Squid Improper Input Validation Vulnerability (CVE-2021-33620)