Description
This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.19.0
References
- GHSA-mw6q-98mp-g8g8
- snyk.io
- security.snyk.io
- CVE-2021-23472
- CWE-79
- CWE-843
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Cross-site scripting in react-bootstrap-table - CVE-2021-23398
- Cross-site Scripting in bootstrap-table - CVE-2022-1726
- Cross-site Scripting in Bootstrap-3-Typeahead - CVE-2019-10215
- Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components - CVE-2025-1647
You might also like:
- Tags:
- npm
- bootstrap-table
Anything's wrong? Let us know Last updated on January 23, 2023


