Impact
DOMSanitizer performs input validation against href and xlink:href attributes, but its isDangerousUrl() function mistakenly allows data: URLs that are Base64‑encoded to bypass the onload substring check. Because the malicious payload inside the data URL is hidden until decoded, the sanitization fails and the contained script or event handler can execute, leading to a cross‑site scripting vulnerability.
Affected Systems
The vulnerability affects the rhukster:dom‑sanitizer package, specifically all versions prior to 1.0.15. The library is used in PHP applications that sanitize DOM, SVG, or MathML content.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. Based on the description, the likely attack vector involves an attacker feeding crafted link attributes into the sanitizer, which is a local or remote injection depending on how the library is used. The weakness is an input‑validation flaw (CWE‑20).
OpenCVE Enrichment