Vulnerabilities/

Bootstrap Vulnerable to Cross-Site Scripting

Severity:
Medium

Description

Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.

Recommendation

Update the bootstrap-sass package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
bootstrap-sass
Anything's wrong? Let us know Last updated on August 01, 2024

This issue is available in SmartScanner Professional

See Pricing