Vulnerabilities/

Cross-site scripting in bootstrap-select

Severity:
Medium

Description

bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Update the bootstrap-select package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
bootstrap-select
Anything's wrong? Let us know Last updated on November 25, 2024

This issue is available in SmartScanner Professional

See Pricing