Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 RubyGems

Bootstrap Vulnerable to Cross-Site Scripting

GHSA-9v3m-8fp8-mj99 · CVE-2019-8331

Published · Modified

Description

Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.

Recommendation

For bootstrap 4.x upgrade to 4.3.1 or later.
For bootstrap 3.x upgrade to 3.4.1 or later.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes