-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Vulnerable Package issue exists @ Npm-bootstrap-3.1.1 in branch main
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
Namespace: CxDemoInABoxRepos
Repository: Java-Webgoat
Repository Url: https://github.com/CxDemoInABoxRepos/Java-Webgoat
CxAST-Project: CxDemoInABoxRepos/Java-Webgoat
CxAST platform scan: 188de2bd-a9df-4b09-95f7-dd05d6f06695
Branch: main
Application: Java-Webgoat
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
CWE: CWE-79
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 3.4.1
References
Pull request
Issue
Commit