Description
This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.19.0
References
Could your website be exposed too?
SmartScanner can check your website for Cross-site Scripting in bootstrap-table - bootstrap-table and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site scripting in react-bootstrap-table - CVE-2021-23398
- Cross-site Scripting in bootstrap-table - CVE-2022-1726
- Cross-site Scripting in Bootstrap-3-Typeahead - CVE-2019-10215
- Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components - CVE-2025-1647


