PT-2019-5302 · Twitter+4 · Bootstrap+4

CVE-2019-8331

·

Published

2019-02-20

·

Updated

2026-07-16

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bootstrap versions prior to 3.4.1 for 3.x and 4.3.1 for 4.x
Description The issue is related to Cross-Site Scripting (XSS) in the tooltip or popover data-template attribute of the Bootstrap toolkit. This is due to a lack of input sanitization, which may allow an attacker to execute arbitrary JavaScript. The vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations For Bootstrap 4.x, upgrade to 4.3.1 or later. For Bootstrap 3.x, upgrade to 3.4.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4670
ALSA-2025_16880
BDU:2020-02249
CESA-2020_3936
CESA-2020_4670
CESA-2020_4847
CVE-2019-8331
GHSA-9V3M-8FP8-MJ99
RHSA-2019:3023
RHSA-2019:3024
RHSA-2020:3247
RHSA-2020:3936
RHSA-2020:4670
RHSA-2020:4847
RHSA-2020:5571
RHSA-2020_3936
RHSA-2020_4670
RHSA-2020_4847
RHSA-2022:8848
RHSA-2022:8865
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RLSA-2020:4670
RLSA-2020:4847

Affected Products

Almalinux
Bootstrap
Centos
Red Hat
Rocky Linux