CVE-2023-46998
Summary
| CVE | CVE-2023-46998 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-07 05:15:00 UTC |
| Updated | 2023-11-14 18:27:00 UTC |
| Description | Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - soy-oreocato/CVE-2023-46998 | github.com | ||
| Document or fix possible XSS vulnerability (via jquery) · Issue #661 · bootboxjs/bootbox · GitHub | github.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995936 NodeJs (Npm) Security Update for bootbox (GHSA-m4ch-4m5f-2gp6)