Description
This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
Remediation
References
Related Vulnerabilities
Apache Traffic Server Exposure of Resource to Wrong Sphere Vulnerability (CVE-2018-8040)
WordPress Plugin Social Networking & E-commerce Arbitrary File Upload (0.0.32)
WordPress Plugin WP Font Awesome Cross-Site Scripting (1.7.8)
WordPress Plugin Protected Posts Logout Button Cross-Site Request Forgery (1.4.4)