PublicCVE

CVE-2017-0928

UNRATEDJSON exportCreate alert

Description

html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.

Affected products