CVE-2021-23472

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/11/2021
Last modified:
23/01/2023

Description

This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bootstrap-table:bootstrap_table:*:*:*:*:*:*:*:* 1.19.1 (excluding)