CVE-2019-16728: XSS
Published Sep 24, 2019
·Updated
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
Affected Software
4 affected componentsFixes available
npm/dompurify<2.0.3
2.0.3
IBM Security Verify Privilege On-Premises<=All
cure53 DOMPurify<2.0.1
Debian Debian Linux=9.0
Event History
Sep 24, 2019
CVE Published
via MITRE·04:02 AM
Data Sourced
via MITRE·04:02 AM
Description
Aug 28, 2020
Advisory Published
09:25 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-16728.
2
What is the severity level of CVE-2019-16728?
The severity of CVE-2019-16728 is medium (6.1).
3
What is the affected software for CVE-2019-16728?
The affected software for CVE-2019-16728 includes versions of `dompurify` prior to 2.0.3 and IBM Security Verify Privilege On-Premises (all versions).
4
How does the vulnerability in CVE-2019-16728 occur?
The vulnerability in CVE-2019-16728 occurs due to an XSS filter bypass in `dompurify` caused by improper validation of user-supplied input.
5
How can I fix the vulnerability in CVE-2019-16728?
To fix the vulnerability in CVE-2019-16728, upgrade to version 2.0.3 or later of `dompurify` or apply the necessary security patches provided by the software vendor.