Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-48910 PoC — DOMPurify vulnerable to tampering by prototype polution

Source
Associated Vulnerability
Title:DOMPurify vulnerable to tampering by prototype polution (CVE-2024-48910)
Description:DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
Readme
# CVE-2024-48910 Proof of Concept - Live Demo

File Snapshot

[4.0K] /data/pocs/6fb2c6821f404f125927d85a6a177f34268ee993 ├── [ 266] package.json ├── [ 29K] package-lock.json ├── [4.0K] public │   └── [9.5K] index.html ├── [ 47] README.md └── [2.5K] server.js 2 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →