Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h73q-5wmj-q8pj

Опубликовано: 29 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross site scripting in datatables.net

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

Пакеты

Наименование

datatables.net

npm
Затронутые версииВерсия исправления

< 1.11.3

1.11.3

EPSS

Процентиль: 78%
0.01975
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.1
ubuntu
почти 5 лет назад

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

CVSS3: 6.1
redhat
почти 5 лет назад

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

CVSS3: 3.1
nvd
почти 5 лет назад

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

msrc
7 месяцев назад

Cross-site Scripting (XSS)

CVSS3: 3.1
debian
почти 5 лет назад

This affects the package datatables.net before 1.11.3. If an array is ...

EPSS

Процентиль: 78%
0.01975
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79