CVE-2022-1726

MEDIUM6.8EPSS 0.34%

Cross-site Scripting in bootstrap-table

Published: 5/17/2022Modified: 11/8/2023
Also known as:GHSA-grw5-g9h2-wpg8DEBIAN-CVE-2022-1726

Description

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.8CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

References (5)