Reflected cross-site scripting (XSS) In bootstrap
Description
Bootstrap vulnerable to Cross-Site Scripting (XSS) In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 4.1.2, 4.1.2, 3.4.0, 3.4.0, 3.4.0, 4.1.2 | ||
rubygems | 3.4.0 | ||
maven | 4.1.2, 3.4.0 | ||
debian 13 | 3.4.0+dfsg-1 | ||
npm | 3.4.0, 4.1.2 | ||
nuget | 4.1.2 | ||
packagist | 3.4.0, 4.1.2 | ||
rubygems | 4.1.2 | ||
debian 12 | 3.4.0+dfsg-1 | ||
nuget | 3.4.0 |
1-10 of 15
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27.