MEDIUM 6.1 RubyGems

Bootstrap Cross-site Scripting vulnerability

GHSA-7mvr-5x2g-wfc8 · CVE-2018-14042

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes