{"id":"GHSA-mw6q-98mp-g8g8","summary":"Cross-site Scripting in bootstrap-table","details":"This affects all versions of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.","aliases":["CVE-2021-23472"],"modified":"2025-01-14T09:12:06.380320Z","published":"2021-11-08T17:54:46Z","database_specific":{"github_reviewed_at":"2021-11-04T17:00:48Z","nvd_published_at":"2021-11-03T18:15:00Z","cwe_ids":["CWE-79","CWE-843"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23472"},{"type":"PACKAGE","url":"https://github.com/wenzhixin/bootstrap-table"},{"type":"WEB","url":"https://github.com/wenzhixin/bootstrap-table/blob/develop/src/utils/index.js%23L218"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1910690"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1910689"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBWENZHIXIN-1910687"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910688"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597"}],"affected":[{"package":{"name":"bootstrap-table","ecosystem":"npm","purl":"pkg:npm/bootstrap-table"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.19.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-mw6q-98mp-g8g8/GHSA-mw6q-98mp-g8g8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}