CVE-2019-20921
30.09.2020, 18:15
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
Vendor | Product | Version |
---|---|---|
snapappointments | bootstrap-select | 𝑥 < 1.13.6 |
𝑥
= Vulnerable software versions
References