The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special HTML comments cannot be filtered and sanitized. This allows for a bypass of the cross-site scripting mechanism of `typo3/html-sanitizer`. This issue has been addressed in versions 1.0.7 and 2.0.16 of the `typo3/html-sanitizer` package. Users are advised to upgrade. There are no known workarounds for this issue.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-09-13T16:55:10.000Z
Updated: 2025-04-23T17:11:55.867Z
Reserved: 2022-07-15T00:00:00.000Z
Link: CVE-2022-36020
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T09:51:59.866Z
 NVD
                        NVD
                    Status : Modified
Published: 2022-09-13T17:15:08.250
Modified: 2024-11-21T07:12:11.947
Link: CVE-2022-36020
 Redhat
                        Redhat
                    No data.