This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2021-09-27T16:35:18.234764Z

Updated: 2024-09-16T18:39:20.468Z

Reserved: 2021-01-08T00:00:00

Link: CVE-2021-23445

cve-icon Vulnrichment

Updated: 2024-08-03T19:05:55.898Z

cve-icon NVD

Status : Modified

Published: 2021-09-27T17:15:08.137

Modified: 2024-11-21T05:51:46.320

Link: CVE-2021-23445

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-09-27T00:00:00Z

Links: CVE-2021-23445 - Bugzilla