VDB
Sign up
MEDIUM6.1

GHSA-m4ch-4m5f-2gp6

Bootbox.js Cross Site Scripting vulnerability

Details

Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootbox
Introduced in: 3.2.0

No fixed version published yet for bootbox (npm). Pin to a known-safe version or switch to an alternative.

References