Description
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
Remediation
References
https://github.com/bootboxjs/bootbox/issues/661
https://github.com/soy-oreocato/CVE-2023-46998/
Related Vulnerabilities
CVE-2023-40014 Vulnerability in npm package @openzeppelin/contracts
CVE-2023-29199 Vulnerability in npm package vm2
CVE-2023-48967 Vulnerability in maven package org.noear:solon.serialization.fury
CVE-2019-11003 Vulnerability in maven package org.webjars.npm:materialize-css
CVE-2023-32697 Vulnerability in maven package org.xerial:sqlite-jdbc