CVE-2022-1726
MEDIUM6.8EPSS 0.34%Cross-site Scripting in bootstrap-table
Published: 5/17/2022Modified: 11/8/2023
Description
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.
Affected packages (2)
- Debian/zoneminderfrom 0
- npm/bootstrap-tablefrom 0, < 1.20.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-1726
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-1726
- PATCHhttps://github.com/wenzhixin/bootstrap-table
- WEBhttps://github.com/wenzhixin/bootstrap-table/commit/b4a1e5dd332be652e0bc376fd9256886cf4bbde9
- WEBhttps://huntr.dev/bounties/9b85cc33-0395-4c31-8a42-3a94beb2efea