Description
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2626 Vulnerability (CVE-2019-2626)
Moodle 7PK - Security Features Vulnerability (CVE-2015-5331)
Oracle JRE CVE-2020-2781 Vulnerability (CVE-2020-2781)
WordPress Plugin Salon booking system Cross-Site Scripting (7.9.3)
Moodle Improper Control of Generation of Code (Code Injection) (CVE-2019-14827)