cve/2019/CVE-2019-16728.md
2024-05-26 14:27:05 +02:00

606 B

CVE-2019-16728

Description

DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.

POC

Reference

No PoCs from references.

Github