← back
CVE-2022-1291highCWE-79

XSS vulnerability with default `onCellHtmlData` function in hhurz/tableexport.jquery.plugin

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.6epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party servers
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L