Vulnerability GHSA-vxmc-5x29-h64v
Medium Risk
MEDIUM RISK
CVSS Score: 6.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
July 11, 2024 at 06:31 PM UTC
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
3.1.1 - 3.4.1
3.1.1 - 3.4.1
Summary
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
Details
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 year ago
Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components
3.4.1 GHSA-q58r-hwc8-rm9j
3.4.1 GHSA-q58r-hwc8-rm9j
Medium Risk
4 years ago
Bootstrap vulnerable to Cross-Site Scripting (XSS)
3.1.1 - 3.3.7 and 4.0.0 - 4.1.1 GHSA-3wqf-4x89-9g79
3.1.1 - 3.3.7 and 4.0.0 - 4.1.1 GHSA-3wqf-4x89-9g79
Medium Risk
7 years ago
Bootstrap Vulnerable to Cross-Site Scripting
3.1.1 - 3.4.0 and 4.0.0 - 4.3.0 GHSA-9v3m-8fp8-mj99
3.1.1 - 3.4.0 and 4.0.0 - 4.3.0 GHSA-9v3m-8fp8-mj99
Medium Risk
7 years ago
bootstrap Cross-site Scripting vulnerability
0.0.1 - 3.3.7 GHSA-ph58-4vrj-w6hr
0.0.1 - 3.3.7 GHSA-ph58-4vrj-w6hr
Medium Risk
7 years ago
XSS vulnerability that affects bootstrap
0.0.1 - 3.3.7 GHSA-3mgp-fx93-9xv5
0.0.1 - 3.3.7 GHSA-3mgp-fx93-9xv5
Impacted packages
Timeline
Published
2 years ago
July 11, 2024 at 06:31 PM UTC
Last Modified
29 days ago
September 10, 2026 at 03:50 AM UTC