CVE-2015-6584

EPSS 0.24%

DataTable Vulnerable to Cross-Site Scripting

發布日:2020/8/31修改日:2024/12/3
也稱為:GHSA-4mv4-gmmf-q382DEBIAN-CVE-2015-6584

描述

Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php. ## Recommendation Update to a version greater than 1.10.8. A [fix](https://github.com/DataTables/DataTablesSrc/commit/ccf86dc5982bd8e16d) appears in [version 1.10.10](https://github.com/DataTables/DataTablesSrc/commits/1.10.10?after=9780a3693572757d87bf70e48bd7555faf974f28+34&branch=1.10.10&qualified_name=refs%2Ftags%2F1.10.10).

受影響套件(3)

參考連結(12)