Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-1726

Опубликовано: 16 мая 2022
Источник: debian
EPSS Низкий

Описание

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderunfixedpackage

Примечания

  • https://huntr.dev/bounties/9b85cc33-0395-4c31-8a42-3a94beb2efea

  • src:zoneminder embedds bootstrap-table-export.js in debian/missing-sources/

  • https://github.com/wenzhixin/bootstrap-table/commit/66ef886d5d325777c8727274c9e018f9c17bc0b9 (1.20.2)

  • Only supported for trusted users/behind auth, see README.debian.security

EPSS

Процентиль: 35%
0.00143
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 3 лет назад

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVSS3: 5.4
nvd
больше 3 лет назад

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVSS3: 6.8
github
больше 3 лет назад

Cross-site Scripting in bootstrap-table

EPSS

Процентиль: 35%
0.00143
Низкий