Loading
Generated remediation guidance and an executive summary. No account required.
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
Use CWE-200, Apostrophecms vendor hub and Sanitize-Html product page to widen CVE-2024-21501 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40186, CVE-2014-125128 and CVE-2019-25225 for nearby disclosures in the same product family.