CVE-2021-23472
Cross-site Scripting (XSS)
Severity Score
6.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
6
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
Esto afecta a las versiones anteriores a la 1.19.1 del paquete bootstrap-table. Una vulnerabilidad de confusión de tipos puede llevar a una evasión de la sanitización de la entrada cuando la entrada proporcionada a la función escapeHTML es un array (en lugar de una cadena) incluso si el atributo escape está establecido
*Credits:
Alessio Della Libera of Snyk Research Team
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-01-08 CVE Reserved
- 2021-11-03 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://github.com/wenzhixin/bootstrap-table/blob/develop/src/utils/index.js%23L218 | Broken Link |
URL | Date | SRC |
---|---|---|
https://security.snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597 | 2024-09-17 | |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1910690 | 2024-09-17 | |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1910689 | 2024-09-17 | |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBWENZHIXIN-1910687 | 2024-09-17 | |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910688 | 2024-09-17 | |
https://snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597 | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bootstrap-table Search vendor "Bootstrap-table" | Bootstrap Table Search vendor "Bootstrap-table" for product "Bootstrap Table" | < 1.19.1 Search vendor "Bootstrap-table" for product "Bootstrap Table" and version " < 1.19.1" | - |
Affected
|