Lucene search

K
osvGoogleOSV:GHSA-4MV4-GMMF-Q382
HistoryAug 31, 2020 - 10:42 p.m.

DataTable Vulnerable to Cross-Site Scripting

2020-08-3122:42:29
Google
osv.dev
17

EPSS

0.002

Percentile

59.6%

Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.

Recommendation

Update to a version greater than 1.10.8. A fix appears in version 1.10.10.