Description
All version of bootbox are vulnerable to Cross-Site Scripting. The package does not sanitize user input in the provided dialog boxes, allowing attackers to inject HTML code and execute arbitrary JavaScript.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.5.2
References
Related Issues
- Bootbox.js Cross Site Scripting vulnerability - CVE-2023-46998
- RSSHub Cross-site Scripting vulnerability caused by internal media proxy - CVE-2024-27926
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes - CVE-2024-29203
You might also like:
- Tags:
- npm
- bootbox
Anything's wrong? Let us know Last updated on January 09, 2023


