We found results for “”
CVE-2019-10215
Good to know:
Date: October 8, 2019
Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.
Language: JS
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version syscover/pulsar - v2.0.17;syscover/pulsar - 1.0;syscover/pulsar - v2.0.19;syscover/pulsar - no_fix;syscover/pulsar - v2.0.12;tellaw/sunshine-admin-bundle - v0.9.21;tellaw/sunshine-admin-bundle - v0.9.10;tellaw/sunshine-admin-bundle - v0.9.23;openclassify/openclassify - dev-master;openclassify/openclassify - dev-vedatakdogan;openclassify/openclassify - dev-emrullahardc-patch-1;openclassify/openclassify - dev-fatihalp-patch-3;openclassify/openclassify - dev-newcurrency;openclassify/openclassify - 3.10.x-dev;openclassify/openclassify - dev-revert-1341-srdr-curr;openclassify/openclassify - dev-vedatakd;openclassify/openclassify - dev-queued-reset-password-email-link-issue;openclassify/openclassify - dev-laravel-upgrade-10;openclassify/openclassify - 4857.x-dev;openclassify/openclassify - dev-sezer;openclassify/openclassify - dev-img-carousel;openclassify/openclassify - dev-muammertop_franch;openclassify/openclassify - dev-vue-compile;openclassify/openclassify - dev-muammer2;openclassify/openclassify - 5881.x-dev;openclassify/openclassify - dev-docker;openclassify/openclassify - dev-detached2;openclassify/openclassify - dev-container-hotfix;openclassify/openclassify - dev-muammer_alibaba;openclassify/openclassify - dev-l10n_master36;openclassify/openclassify - 2.0.30;openclassify/openclassify - dev-serdarekremcakir-patch-1;openclassify/openclassify - dev-l10n_master40;openclassify/openclassify - dev-gg-minor-changes;openclassify/openclassify - 4798.x-dev;openclassify/openclassify - dev-vedat;openclassify/openclassify - dev-moradi;openclassify/openclassify - dev-samettrans;openclassify/openclassify - dev-mostafamoradi;openclassify/openclassify - dev-l10n_master32;openclassify/openclassify - dev-l10n_master38;Bootstrap-3-Typeahead - no_fix;jetcms/soa-sentinel - no_fix;jetcms/soa-sentinel - 3.0.1;grumpydictator/firefly-iii - dev-dependabot/composer/develop/vimeo/psalm-4.4.1;grumpydictator/firefly-iii - dev-dependabot/composer/develop/vimeo/psalm-4.6.2;grumpydictator/firefly-iii - dev-dependabot/composer/develop/vimeo/psalm-4.6.3;grumpydictator/firefly-iii - dev-dependabot/composer/develop/ramsey/uuid-4.4.0;grumpydictator/firefly-iii - dev-dependabot/composer/develop/vimeo/psalm-4.3.2;grumpydictator/firefly-iii - dev-dependabot/composer/develop/vimeo/psalm-4.6.1;grumpydictator/firefly-iii - dev-dependabot/composer/develop/ramsey/uuid-4.6.0;grumpydictator/firefly-iii - 4.6.13;grumpydictator/firefly-iii - dev-dependabot/npm_and_yarn/develop/vite-4.5.0;zoujingli/thinkadmin - v4.0.0;skobkin/point-tools - no_fix;guoyu/yii2admin - no_fix;sergeyugai/badpack - dev-dependabot/composer/symfony/http-kernel-5.4.20;anomaly/tags-field_type - v2.0.4;anomaly/tags-field_type - v2.1.3;anomaly/tags-field_type - v2.0.8;anomaly/tags-field_type - 2.3.x-dev;anomaly/keywords-field_type - v2.0.8;anomaly/keywords-field_type - v2.1.3;anomaly/keywords-field_type - v2.0.4;anomaly/keywords-field_type - 2.3.x-dev;intelogie/bootstrap-3-typeahead - no_fix;WebVella.TagHelpers - 1.1.4;WebVella.TagHelpers - 1.0.33;nosh2/nosh2 - dev-dependabot/composer/guzzlehttp/guzzle-7.4.3;nosh2/nosh2 - dev-dependabot/npm_and_yarn/ini-1.3.8;nosh2/nosh2 - no_fix;anomaly/files-field_type - v2.3.9;anomaly/files-field_type - v2.3.7;anomaly/files-field_type - no_fix;anomaly/files-field_type - v2.3.18;anomaly/files-field_type - v2.3.0;anomaly/files-field_type - v2.2.19;anomaly/files-field_type - v2.2.10;livecms/core - v0.1.1;livecms/core - v1.0.1;TDSCore.Tempalte - 1.3.0;vinala/kernel - dev-database-slowness-repairing;zhangsong9008/thinkadmin - v4.x-dev;pyshnov/core - no_fix;gegmar/cluber - no_fix;gegmar/cluber - v0.1.0;gegmar/cluber - dev-dependabot/composer/laravel/framework-6.20.14;i9code/laravelmetronic3 - no_fix;e282486518/yii2admin - no_fix;bootstrap-3-typeahead - no_fix;shengfai/laravel-admin - 1.1.21;shengfai/laravel-admin - no_fix;shengfai/laravel-admin - 1.1.19;eng-mmarouf/metronic - no_fix;anomaly/keywords-field-type - v2.1.0;anomaly/keywords-field-type - v2.2.0;i9code/metronic - no_fix;bassjobsen/bootstrap-3-typeahead - dev-revert-283-master;maioradv/admin2-cdn - no_fix;visiosoft/media-field_type - dev-master;visiosoft/media-field_type - no_fix;ristorantino/plugins - 2.0.0-dev1;samadmin/samadmin - no_fix;i9code/laravelmetronic - no_fix;Mesonic - no_fix;pyshnov/realty - 0.1.1;dukeann/laradmin - 1.0;mshule/laravel-pipes - v1.2;igeekspace/twothink - no_fix;syscontrollers/admin - v0.0.4;olee/sales - no_fix;Progressive.TagHelpers - no_fix;livecms/livecms - dev-master;Module.Template.Test - no_fix;i9code/laravelmetronic2 - no_fix;aerni/translator - dev-dependabot/npm_and_yarn/minimist-1.2.6;sebardo/admin - no_fix;kayrules/solatjakim-api-site - v1.0;michalwolinski/wbiztool-laravel - dev-dependabot/composer/symfony/http-foundation-4.4.7;org.webjars.npm:bootstrap-3-typeahead:no_fix;org.webjars.bower:bootstrap3-typeahead-extended:no_fix;org.webjars:Bootstrap-3-Typeahead:no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | MEDIUM |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


