Description
There is a cross-site scripting vulnerability with default onCellHtmlData function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. This can result in transmitting cookies to third-party servers and/or sending data from secure sessions to third-party servers.
Recommendation
Update the tableexport.jquery.plugin package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.25.0
- Patched version(s): 1.25.0
References
Related Issues
- Cross-site Scripting in jquery.json-viewer - CVE-2022-30241
- Cross-site Scripting in fullpage.js - CVE-2022-1330
- Cross-site Scripting in Auth0 Lock - CVE-2022-29172
- Cross-site Scripting in vditor (GHSA-pq37-4c4g-v38c) - CVE-2022-0341
- Tags:
- npm
- tableexport.jquery.plugin
Anything's wrong? Let us know Last updated on January 27, 2023