Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 RubyGems

Bootstrap Cross-site Scripting vulnerability

GHSA-7mvr-5x2g-wfc8 · CVE-2018-14042

Published · Modified

Description

In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes