Description
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
Remediation
References
https://github.com/bootboxjs/bootbox/issues/661
https://github.com/soy-oreocato/CVE-2023-46998/
Related Vulnerabilities
CVE-2022-39382 Vulnerability in npm package @keystone-6/core
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee9:jetty-ee9-servlets
CVE-2021-33561 Vulnerability in maven package com.shopizer:shopizer