CVE-2022-1726Cross-site Scripting in Bootstrap-table

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 65.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 17

Description

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
GHSA
Cross-site Scripting in bootstrap-table2022-05-17
OSV
Cross-site Scripting in bootstrap-table2022-05-17
OSV
CVE-2022-1726: Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table pr2022-05-16

📋Vendor Advisories

1
Debian
CVE-2022-1726: zoneminder - Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions:...2022