VYPR
Medium severity6.1NVD Advisory· Published Nov 7, 2023· Updated Jun 17, 2026

CVE-2023-46998

CVE-2023-46998

Description

Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
bootboxnpm
>= 3.2.0, <= 6.0.0

Affected products

3
  • cpe:2.3:a:bootboxjs:bootbox:*:*:*:*:*:node.js:*:*
    Range: >=3.2.0,<=6.0.0
  • BootBox/Bootbox.jsdescription
  • ghsa-coords
    Range: >= 3.2.0, <= 6.0.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.