mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 09:12:08 +00:00
798 B
798 B
CVE-2021-23445
Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
POC
Reference
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1715371
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1715376
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1540544