Description
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0995 | bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser. |
Github GHSA |
GHSA-7c82-mp33-r854 | Cross-site scripting in bootstrap-select |
References
History
Mon, 25 Nov 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-25T17:45:55.390Z
Reserved: 2020-09-30T00:00:00.000Z
Link: CVE-2019-20921
No data.
Status : Modified
Published: 2020-09-30T18:15:18.007
Modified: 2024-11-25T18:15:06.253
Link: CVE-2019-20921
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA