Lucene search

K
redhatcveRedhat.comRH:CVE-2018-20676
HistoryApr 04, 2020 - 5:27 p.m.

CVE-2018-20676

2020-04-0417:27:53
redhat.com
access.redhat.com
33

0.003 Low

EPSS

Percentile

70.0%

A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting, caused by improper validation of user-supplied input by the tooltip data-viewport attribute. This flaw allows a remote attacker to execute a script in a victim’s Web browser within the security context of the hosting Web site, which can lead to stealing the victim’s cookie-based authentication credentials.