PT-2020-10876 · Twitter · Bootstrap-Select

CVE-2019-20921

·

Published

2020-09-03

·

Updated

2024-11-25

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions bootstrap-select versions prior to 1.13.6
Description The issue allows Cross-Site Scripting (XSS) due to the failure to escape title values in OPTION elements. This may enable attackers to execute arbitrary JavaScript in a victim's browser.
Recommendations For versions prior to 1.13.6, update to version 1.13.6 or later to resolve the issue. As a temporary workaround, consider disabling the use of title values in OPTION elements until a patch is available. Restrict access to potentially vulnerable web pages to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20921
GHSA-7C82-MP33-R854
GHSA-9R7H-6639-V5MW
RHSA-2021:1169
RHSA-2021:1186
SNYK-JS-BOOTSTRAPSELECT-570457

Affected Products

Bootstrap-Select