ZeroHour

CVE-2021-23445

PoC ×3
CVSS 3.1
6.1 medium
EPSS
2%p79
Published
()
Modified
Description

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

Vendors
datatables
Products
datatables.net
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.