VDB
Sign up
HIGH

GHSA-9r7h-6639-v5mw

Cross-Site Scripting in bootstrap-select

Quick fix

GHSA-9r7h-6639-v5mw — bootstrap-select: upgrade to the fixed version with the command below.

npm install bootstrap-select@1.13.6

Details

Versions of `bootstrap-select` prior to 1.13.6 are vulnerable to Cross-Site Scripting (XSS). The package does not escape `title` values on `<option>` tags. This may allow attackers to execute arbitrary JavaScript in a victim's browser.

## Recommendation

Upgrade to version 1.13.6 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap-select
Introduced in: 0Fixed in: 1.13.6
Fixnpm install bootstrap-select@1.13.6

References