GHSA-j636-crp3-m584
Dashboard / Vulnerabilities / GHSA-j636-crp3-m584
Summary: Cross-site Scripting in tableexport.jquery.plugin
Details: There is a cross-site scripting vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. This can result in transmitting cookies to third-party servers and/or sending data from secure sessions to third-party servers.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-1291, https://github.com/hhurz/tableexport.jquery.plugin/commit/dcbaee23cf98328397a153e71556f75202988ec9, https://github.com/hhurz/tableexport.jquery.plugin, https://huntr.dev/bounties/49a14371-6058-47dd-9801-ec38a7459fc5
Affected packages
Package
Name: tableexport.jquery.plugin
Purl: pkg:npm/tableexport.jquery.plugin
Affected ranges
Type: SEMVER
Events:
