Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Recommendation
Update the datatables.net package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.11.3
- Patched version(s): 1.11.3
References
Could your website be exposed too?
SmartScanner can check your website for Cross site scripting in datatables.net and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in epubjs - CVE-2021-33040
- DataTable Vulnerable to Cross-Site Scripting - CVE-2015-6584
- Cross-site Scripting in React Draft Wysiwyg - CVE-2021-31712
- Options structure open to Cross-site Scripting if passed unfiltered - CVE-2021-29489
You might also like:
See something that needs correcting? Let us knowUpdated June 21, 2024


