Description
All version of bootbox are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject HTML code and execute arbitrary JavaScript.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.5.2
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in bootbox and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Bootbox.js Cross Site Scripting vulnerability - CVE-2023-46998
- RSSHub Cross-site Scripting vulnerability caused by internal media proxy - CVE-2024-27926
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes - CVE-2024-29203
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


