Twitter · Bootstrap · CVE-2016-10735
**Name of the Vulnerable Software and Affected Versions**
Bootstrap versions 2.0.4 through 3.x before 3.4.0
Bootstrap versions 4.x-beta before 4.0.0-beta.2
**Description**
XSS is possible in the `data-target` attribute. This issue is different from other known vulnerabilities.
**Recommendations**
For Bootstrap versions 2.0.4 through 3.x before 3.4.0, update to version 3.4.0 or later to resolve the issue.
For Bootstrap versions 4.x-beta before 4.0.0-beta.2, update to version 4.0.0-beta.2 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the `data-target` attribute until a patch is available.