← Back

CVE-2018-14041

nvd nist
Published: Jul 13, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

Affected (10)

1 product
Bootstrap
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Getbootstrap
From 4.0.0 to 4.1.2
Version 4.0.0 alpha2
Version 4.0.0 alpha3
Version 4.0.0 alpha4
Version 4.0.0 alpha5
Version 4.0.0 alpha6
Version 4.0.0 alpha
Version 4.0.0 beta2
Version 4.0.0 beta3
Version 4.0.0 beta

References (34)

Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.