Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13348
HistoryFeb 14, 2019 - 8:50 a.m.

Cross-site Scripting (XSS)

2019-02-1408:50:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.004 Low

EPSS

Percentile

74.7%

bootstrap is vulnerable to Cross-site Scripting (XSS). The attack exists because it does not escape the data-template, data-content and data-title options for tooltip/popover plugins, allowing to inject malicious script through it.

References