AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-21501

MEDIUM · CVSS 5.3 EPSS 1.02% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-02-24 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-21501
Severity
MEDIUM
CVSS
5.3
EPSS
1.02%

Original NVD Description

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)