Lucene search

K
redhatcveRedhat.comRH:CVE-2018-20677
HistoryApr 08, 2020 - 10:13 p.m.

CVE-2018-20677

2020-04-0822:13:21
redhat.com
access.redhat.com
33

EPSS

0.004

Percentile

73.0%

A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting caused by improper validation of user-supplied input by the affix configuration target property. This flaw allows a remote attacker to execute a script in a victim’s Web browser within the security context of the hosting Web site, which can lead to stealing the victim’s cookie-based authentication credentials.