VDB
Sign up
MEDIUM6.8

GHSA-grw5-g9h2-wpg8

Cross-site Scripting in bootstrap-table

Quick fix

GHSA-grw5-g9h2-wpg8 — bootstrap-table: upgrade to the fixed version with the command below.

npm install bootstrap-table@1.20.2

Details

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap-table
Introduced in: 0Fixed in: 1.20.2
Fixnpm install bootstrap-table@1.20.2

References