Vulnerabilities/

Cross-Site Scripting in bootbox

Severity:
Medium

Description

All version of bootbox are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject HTML code and execute arbitrary JavaScript.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
bootbox
Anything's wrong? Let us know Last updated on January 09, 2023