Description
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.
Recommendation
Update the bootstrap-table package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.20.2
- Patched version(s): 1.20.2
References
Related Issues
- Cross-site Scripting in bootstrap-table - bootstrap-table - CVE-2021-23472
- Cross-site scripting in react-bootstrap-table - CVE-2021-23398
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm - CVE-2022-31175
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - CVE-2022-31175
You might also like:
- Tags:
- npm
- bootstrap-table
Anything's wrong? Let us know Last updated on February 03, 2023


