Vulnerability Description
Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a version from 2012.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sprymedia | Datatables | 1.9.2 |
Related Weaknesses (CWE)
References
- https://cdn.datatables.net/1.9.2/js/jquery.dataTables.jsProduct
- https://gist.github.com/walhajri/711af9b62f6fb25e66a5d9a490deab98ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230406-0003/
- https://cdn.datatables.net/1.9.2/js/jquery.dataTables.jsProduct
- https://gist.github.com/walhajri/711af9b62f6fb25e66a5d9a490deab98ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230406-0003/
FAQ
What is CVE-2021-36713?
CVE-2021-36713 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a ver...
How severe is CVE-2021-36713?
CVE-2021-36713 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36713?
Check the references section above for vendor advisories and patch information. Affected products include: Sprymedia Datatables.