VDB
Sign up
MEDIUM6.1

GHSA-gv5r-9gxr-v74w

Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data

Quick fix

GHSA-gv5r-9gxr-v74w — bootstrap-multiselect: upgrade to the fixed version with the command below.

npm install bootstrap-multiselect@2.0.0

Details

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap-multiselect
Introduced in: 0Fixed in: 2.0.0
Fixnpm install bootstrap-multiselect@2.0.0

References