Описание
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Ссылки
- Release NotesVendor Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.11.3 (исключая)
cpe:2.3:a:datatables:datatables.net:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 55%
0.00327
Низкий
3.1 Low
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 3.1
ubuntu
больше 4 лет назад
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
CVSS3: 6.1
redhat
больше 4 лет назад
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
CVSS3: 3.1
debian
больше 4 лет назад
This affects the package datatables.net before 1.11.3. If an array is ...
EPSS
Процентиль: 55%
0.00327
Низкий
3.1 Low
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79