GHSA-7c82-mp33-r854
Dashboard / Vulnerabilities / GHSA-7c82-mp33-r854
GHSA-7c82-mp33-r854
Summary: Cross-site scripting in bootstrap-select
Details: bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-20921, https://github.com/snapappointments/bootstrap-select/issues/2199, https://github.com/snapappointments/bootstrap-select/commit/ab6e068748040cf3cda5859f6349b382402b8767, https://github.com/snapappointments/bootstrap-select, https://issues.jtl-software.de/issues/SHOP-7964, https://snyk.io/vuln/SNYK-JS-BOOTSTRAPSELECT-570457
Affected packages
Package
Name: bootstrap-select
Purl: pkg:npm/bootstrap-select
Affected ranges
Type: SEMVER
Events:
