Lucene search

K
osvGoogleOSV:GHSA-9V3M-8FP8-MJ99
HistoryFeb 22, 2019 - 8:54 p.m.

Bootstrap Vulnerable to Cross-Site Scripting

2019-02-2220:54:47
Google
osv.dev
186

EPSS

0.003

Percentile

69.5%

Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.

Recommendation

For bootstrap 4.x upgrade to 4.3.1 or later.
For bootstrap 3.x upgrade to 3.4.1 or later.

References