Vulnerabilities/

Bootstrap Cross-Site Scripting (XSS) vulnerability

Severity:
Medium

Description

A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an tag due to inadequate sanitization.

Recommendation

Update the bootstrap package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
bootstrap
Anything's wrong? Let us know Last updated on April 14, 2025

This issue is available in SmartScanner Professional

See Pricing