Vulnerability GHSA-4p24-vmcr-4gqj

Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 years ago
January 17, 2019 at 01:57 PM UTC
Bootstrap Cross-site Scripting vulnerability
3.1.1 - 3.3.7 and 4.0.0-beta
3.1.1 - 3.3.7 and 4.0.0-beta

Summary

Bootstrap Cross-site Scripting vulnerability

Details

In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041.

See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info.

Timeline

Published
7 years ago
January 17, 2019 at 01:57 PM UTC
Fixed (4.0.0-beta.2)
8 years ago
October 19, 2017 at 07:23 PM UTC
Fixed (4.0.0-beta.2)
8 years ago
October 19, 2017 at 07:27 PM UTC
Fixed (3.4.0)
7 years ago
December 13, 2018 at 11:45 PM UTC
Fixed (3.4.0)
7 years ago
December 13, 2018 at 11:50 PM UTC
Fixed (3.4.0)
7 years ago
December 14, 2018 at 12:37 PM UTC
Fixed (3.4.0)
7 years ago
December 14, 2018 at 12:38 PM UTC
Fixed (3.4.0)
7 years ago
December 16, 2018 at 04:18 AM UTC
Fixed (3.4.0)
Unknown
Unknown
Fixed (4.0.0-beta.2)
Unknown
Unknown
Last Modified
29 days ago
September 10, 2026 at 03:47 AM UTC