Vulnerabilities/

Bootstrap Vulnerable to Cross-Site Scripting (GHSA-9v3m-8fp8-mj99)

Severity:
Medium

Description

Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.

Recommendation

Update the bootstrap package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
bootstrap
Anything's wrong? Let us know Last updated on August 01, 2024

This issue is available in SmartScanner Professional

See Pricing