{"id":"UBUNTU-CVE-2023-46998","details":"Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.","modified":"2026-05-20T16:13:53.312733708Z","published":"2023-11-07T05:15:00Z","upstream":["CVE-2023-46998"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-46998"},{"type":"REPORT","url":"https://github.com/bootboxjs/bootbox/issues/661"},{"type":"REPORT","url":"https://github.com/soy-oreocato/CVE-2023-46998/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-46998"}],"affected":[{"package":{"name":"libjs-bootbox","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libjs-bootbox?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.1.3~dfsg-2","5.3.2~dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-bootbox","binary_version":"5.3.2~dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46998.json"}},{"package":{"name":"libjs-bootbox","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libjs-bootbox?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.5.2~ds-1","5.5.2~ds-2"],"ecosystem_specific":{"binaries":[{"binary_version":"5.5.2~ds-2","binary_name":"libjs-bootbox"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46998.json"}},{"package":{"name":"libjs-bootbox","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libjs-bootbox?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.5.3~ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-bootbox","binary_version":"5.5.3~ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46998.json"}},{"package":{"name":"libjs-bootbox","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libjs-bootbox?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.5.3~ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-bootbox","binary_version":"5.5.3~ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46998.json"}},{"package":{"name":"libjs-bootbox","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libjs-bootbox?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.5.3~ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-bootbox","binary_version":"5.5.3~ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46998.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}