QID 995936
Date Published: 2023-11-16
QID 995936: NodeJs (Npm) Security Update for bootbox (GHSA-m4ch-4m5f-2gp6)
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-m4ch-4m5f-2gp6 for updates and patch information.
Vendor References
- GHSA-m4ch-4m5f-2gp6 -
github.com/advisories/GHSA-m4ch-4m5f-2gp6
CVEs related to QID 995936
Software Advisories
| Advisory ID | Software | Component | Link |
|---|