PT-2019-7534 · Twitter+4 · Bootstrap+4
Aasmacmx
·
Publicado
2019-01-09
·
Atualizado
2025-09-29
·
CVE-2016-10735
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bootstrap versions 2.0.4 through 3.x before 3.4.0
Bootstrap versions 4.x-beta before 4.0.0-beta.2
Description
XSS is possible in the
data-target attribute. This issue is different from other known vulnerabilities.Recommendations
For Bootstrap versions 2.0.4 through 3.x before 3.4.0, update to version 3.4.0 or later to resolve the issue.
For Bootstrap versions 4.x-beta before 4.0.0-beta.2, update to version 4.0.0-beta.2 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
data-target attribute until a patch is available.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Almalinux
Bootstrap
Centos
Red Hat
Rocky Linux