Описание
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Ссылки
- Broken LinkThird Party Advisory
- ExploitPatchThird Party Advisory
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- Broken LinkThird Party Advisory
- ExploitPatchThird Party Advisory
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
Уязвимые конфигурации
EPSS
3.1 Low
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Уязвимость функции escapeHTML программного средства Bootstrap Table, позволяющая нарушителю отказать воздействие на конфиденциальность и целостность защищаемой информации
EPSS
3.1 Low
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2