CVE-2019-25155
Published Oct 31, 2023
·Updated
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Affected Software
2 affected componentsFixes available
npm/dompurify<1.0.11
1.0.11
cure53 DOMPurify<1.0.11
Remediation
Patch Available
Patch Available
Event History
Oct 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Nov 14, 2023
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-25155.
2
What is the severity level of CVE-2019-25155?
The severity level of CVE-2019-25155 is medium with a CVSS score of 6.1.
3
Which software is affected by CVE-2019-25155?
DOMPurify before version 1.0.11 is affected by CVE-2019-25155.
4
What is the impact of CVE-2019-25155?
CVE-2019-25155 allows reverse tabnabbing, which can lead to phishing attacks or the disclosure of sensitive information.
5
How can I fix CVE-2019-25155?
To fix CVE-2019-25155, upgrade DOMPurify to version 1.0.11 or later.