Cross-site Scripting (XSS)
CVE-2021-23445

3.1LOW

Key Information:

Vendor

Datatables

Vendor
CVE Published:
27 September 2021

What is CVE-2021-23445?

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

Affected Version(s)

datatables.net < 1.11.3

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alessio Della Libera of Snyk Research Team
.