Executive brief
bootstrap-select is a JavaScript library that enhances HTML select elements with additional functionality. The library fails to properly escape HTML entities in option element title attributes, allowing attackers to inject malicious JavaScript that executes when users interact with affected dropdown menus. This can lead to session hijacking, credential theft, or malware distribution through compromised web applications.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in bootstrap-select versions before 1.13.6. The root cause is improper sanitization of the title attribute in OPTION elements—the library renders unescaped HTML content in these attributes, allowing JavaScript injection. An attacker can craft a malicious title value (e.g., `title="<img src=x onerror=alert('xss')>"`) that bypasses basic HTML entity encoding. The vulnerability requires user interaction (hovering over or clicking a dropdown option) but no authentication. An attacker can execute arbitrary JavaScript in the victim's browser with the privileges of the origin hosting the vulnerable application. The fix was released in version 1.13.6.
Affected products
- Snap Appointments bootstrap-select before 1.13.6
Timeline
- 2020-09-30: disclosed: NVD published CVE-2019-20921
- 2021-05-07: patched: GHSA advisory published; fix available in bootstrap-select 1.13.6