Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q58r-hwc8-rm9j

Опубликовано: 15 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.6

Описание

Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS). This issue affects Bootstrap version 3.4.1. At time of publication, there is no publicly available patched version.

Пакеты

Наименование

bootstrap

npm
Затронутые версииВерсия исправления

= 3.4.1

Отсутствует

EPSS

Процентиль: 12%
0.00039
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.6
ubuntu
8 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.

CVSS3: 5.6
redhat
8 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.

CVSS3: 5.6
nvd
8 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.

CVSS3: 5.6
debian
8 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'C ...

EPSS

Процентиль: 12%
0.00039
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-79