Vulnerabilities/

Bootstrap Cross-site Scripting vulnerability (GHSA-7mvr-5x2g-wfc8)

Severity:
Medium

Description

In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.

Recommendation

Update the bootstrap-sass package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
bootstrap-sass
Anything's wrong? Let us know Last updated on August 05, 2024

This issue is available in SmartScanner Professional

See Pricing