VDB
Sign up
LOW3.1

GHSA-mw6q-98mp-g8g8

Cross-site Scripting in bootstrap-table

Details

This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap-table
Introduced in: 0

No fixed version published yet for bootstrap-table (npm). Pin to a known-safe version or switch to an alternative.

References