Vulnerabilities/

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Severity:
Medium

Description

In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute.

Recommendation

Update the bootstrap package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
bootstrap
Anything's wrong? Let us know Last updated on August 05, 2024

This issue is available in SmartScanner Professional

See Pricing