CVE-2021-23472
PoC ×6—CVSS 3.1
6.1 medium
EPSS
2%p83
Published
()
Modified
Description
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
- Vendors
- bootstrap-table
- Products
- bootstrap table
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.