### [CVE-2021-23445](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23445) ![](https://img.shields.io/static/v1?label=Product&message=datatables.net&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%201.11.3%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-site%20Scripting%20(XSS)&color=brighgreen) ### Description This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped. ### POC #### Reference - https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371 - https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376 - https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544 #### Github - https://github.com/dellalibera/dellalibera