PT-2019-5302 · Twitter+4 · Bootstrap+4
CVE-2019-8331
·
Publicado
2019-02-20
·
Atualizado
2026-07-16
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bootstrap versions prior to 3.4.1 for 3.x and 4.3.1 for 4.x
Description
The issue is related to Cross-Site Scripting (XSS) in the tooltip or popover data-template attribute of the Bootstrap toolkit. This is due to a lack of input sanitization, which may allow an attacker to execute arbitrary JavaScript. The vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations
For Bootstrap 4.x, upgrade to 4.3.1 or later.
For Bootstrap 3.x, upgrade to 3.4.1 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Almalinux
Bootstrap
Centos
Red Hat
Rocky Linux