Lucene search

K
hackeroneN33dm0n3yH1:1188643
HistoryMay 07, 2021 - 8:48 p.m.

Sifchain: Vulnerable javascript dependency at Main domain

2021-05-0720:48:11
n33dm0n3y
hackerone.com
159

0.008 Low

EPSS

Percentile

81.2%

Hello,

Issue detail,

Burp observed 1 outdated JavaScript libraries with 4 known vulnerabilities.
Burp detected bootstrap version 4.0.0, which has the following vulnerabilities:

CVE-2019-8331: XSS in data-template, data-content and data-title properties of tooltip/popover
CVE-2018-14041: XSS in data-target property of scrollspy
CVE-2018-14040: XSS in collapse data-parent attribute
CVE-2018-14042: XSS in data-container property of tooltip

Host:  https://sifchain.finance
Path:  /wp-content/themes/icos/assets/js/vendor/bootstrap.min.js

{F1293110}

Impact

Potential XSS