Description
Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
Recommendation
Update the bootstrap package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.0.0, < 3.4.1 >= 4.0.0, < 4.3.1** Patched version(s): **3.4.1 4.3.1**
References
Could your website be exposed too?
SmartScanner can check your website for Bootstrap Vulnerable to Cross-Site Scripting - bootstrap and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Bootstrap Vulnerable to Cross-Site Scripting - CVE-2019-8331
- Materialize-css vulnerable to Cross-site Scripting in autocomplete component - CVE-2019-11003
- Bootstrap vulnerable to Cross-Site Scripting (XSS) - CVE-2018-14040
- mxGraph vulnerable to cross-site scripting in color field - CVE-2019-13127


