Security Advisory

CVE-2021-23472

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-11-03 17:25:11
Last updated 2024-09-17 02:56:45
Assigner snyk
CVSS score 3.1
State PUBLISHED

Description

This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.