Cross-site Scripting (XSS)
CVE-2021-23445
3.1LOW
What is CVE-2021-23445?
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Affected Version(s)
datatables.net < 1.11.3
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alessio Della Libera of Snyk Research Team
