MEDIUM6.1
GHSA-m4ch-4m5f-2gp6
Bootbox.js Cross Site Scripting vulnerability
Details
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/bootbox
Introduced in:
3.2.0No fixed version published yet for bootbox (npm). Pin to a known-safe version or switch to an alternative.