Vulnerabilities/

Cross-site Scripting in bootstrap-table - bootstrap-table

Severity:
Low

Description

This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
bootstrap-table
Anything's wrong? Let us know Last updated on January 23, 2023