CVE-2023-46998
npm/bootbox
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
All versions starting from 3.2 up to 6.0
Unfortunately, there is no solution available yet.
2023-11-16
source |