Vulnerabilities/

Cross-site Scripting in Bootstrap-3-Typeahead

Severity:
Medium

Description

Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user’s browser. This issue was introduced in commit dbd1af5bf and has not been fixed.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
bootstrap-3-typeahead
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing