PT-2023-12299 · Jquery · Datatables
Waleed Ibrahim Alhajri
·
Published
2023-03-06
·
Updated
2025-03-07
·
CVE-2021-36713
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DataTables plug-in version 1.9.2 for jQuery
Description
A Cross Site Scripting (XSS) issue allows attackers to run arbitrary code via the
sBaseName parameter to the fnCreateCookie function. This affects a version from 2012.Recommendations
For version 1.9.2, consider disabling the
fnCreateCookie function or restricting the use of the sBaseName parameter to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datatables