Reflected cross-site scripting (XSS) In bootstrap
Description
Bootstrap Cross-site Scripting vulnerability In Bootstrap 4.x before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 4.1.2, 4.1.2, 4.1.2 | ||
nuget | 4.1.2 | ||
npm | 4.1.2 | ||
packagist | 4.1.2 | ||
packagist | 8.7.23, 9.5.4 | ||
rubygems | 4.1.2 | ||
maven | 4.1.2 | ||
packagist | 8.7.23, 9.5.4 | ||
nuget | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22.