CVE-2022-1726

MEDIUM6.8EPSS 0.34%

Cross-site Scripting in bootstrap-table

發布日:2022/5/17修改日:2023/11/8
也稱為:GHSA-grw5-g9h2-wpg8DEBIAN-CVE-2022-1726

描述

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.8CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

參考連結(5)