GHSA-rf66-hmqf-q3fc
Dashboard / Vulnerabilities / GHSA-rf66-hmqf-q3fc
Summary: Improper Neutralization of Input During Web Page Generation in Select2
Details: In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-10744, https://github.com/select2/select2/issues/4587, https://github.com/snipe/snipe-it/pull/6831, https://github.com/snipe/snipe-it/pull/6831/commits/5848d9a10c7d62c73ff6a3858edfae96a429402a, https://github.com/select2/select2
Affected packages
Package
Name: select2
Purl: pkg:npm/select2
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -4.0.6
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
