Security Advisory

CVE-2016-10744

6.1
MEDIUM

Vulnerability Description

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
Published Date March 27, 2019
Official Source NIST NVD Advisory