Product
high
advisory
Attribute Injection in @xmldom/xmldom via Element.setAttribute
1 TTP 1 CVEThe @xmldom/xmldom library fails to validate attribute names during the use of Element.setAttribute, allowing attackers to inject malicious attributes into serialized XML output leading to potential XSS.
@xmldom/xmldom +1
xss
injection
vulnerability
web-application
1t
1c
high
advisory
xmldom requireWellFormed Serialization Bypass
2 TTPs 1 CVEThe xmldom serializer fails to properly validate element and attribute names when the requireWellFormed option is enabled, allowing attackers to inject arbitrary markup via line-terminated strings.
xmldom +3
injection
xss
library-vulnerability
2t
1c
high
advisory
XML Injection Vulnerability in @xmldom/xmldom via Processing Instruction Targets
1 TTP 1 CVEThe @xmldom/xmldom library fails to validate the target parameter in createProcessingInstruction, enabling attackers to break out of XML processing instructions and inject arbitrary content when serializing with the requireWellFormed flag.
@xmldom/xmldom +2
injection
xss
xxe
vulnerability
1t
1c