Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21194 Vulnerability (CVE-2024-21194)
Squid CVE-2024-45802 Vulnerability (CVE-2024-45802)
WebLogic CVE-2021-35620 Vulnerability (CVE-2021-35620)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2021-23841)
WordPress Plugin Drag & Drop File Uploader 'dnd-upload.php' Arbitrary File Upload (0.1)