Lucene search

K
githubGitHub Advisory DatabaseGHSA-4MV4-GMMF-Q382
HistoryAug 31, 2020 - 10:42 p.m.

DataTable Vulnerable to Cross-Site Scripting

2020-08-3122:42:29
CWE-79
GitHub Advisory Database
github.com
147

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

59.6%

Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.

Recommendation

Update to a version greater than 1.10.8. A fix appears in version 1.10.10.

Affected configurations

Vulners
Node
datatablesdatatablesRange<1.10.10
OR
datatablesdatatablesRange<1.10.10
VendorProductVersionCPE
datatablesdatatables*cpe:2.3:a:datatables:datatables:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

59.6%