📦

braintree\/sanitize-url

Vendor: paypal

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.99% Exploit Prob.
Latest CVE CVE-2022-48345 Feb 24

Security Vulnerability Index

Page 1 / 1
6.1 CVSS

sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

EPSS: 0.56%
5.4 CVSS

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

EPSS: 1.42%