4.3
CVSSv2

CVE-2016-10744

Published: 27/03/2019 Updated: 27/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Select2 up to and including 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

select2 select2

Vendor Advisories

Impact: Moderate Public Date: 2019-03-19 CWE: CWE-20 Bugzilla: 1693166: CVE-2016-10744 select2: cross-s ...