VDB
Sign up
MEDIUM6.1

GHSA-h73q-5wmj-q8pj

Cross site scripting in datatables.net

Quick fix

GHSA-h73q-5wmj-q8pj — datatables.net: upgrade to the fixed version with the command below.

npm install datatables.net@1.11.3

Details

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/datatables.net
Introduced in: 0Fixed in: 1.11.3
Fixnpm install datatables.net@1.11.3

References