Lucene search

K
osvGoogleOSV:GHSA-H73Q-5WMJ-Q8PJ
HistorySep 29, 2021 - 5:11 p.m.

Cross site scripting in datatables.net

2021-09-2917:11:28
Google
osv.dev
29
cross site scripting
datatables.net
version 1.11.3
html escape entities
array
contents escaped
software

EPSS

0.002

Percentile

61.3%

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.