PT-2019-7534 · Twitter+4 · Bootstrap+4

Aasmacmx

·

Published

2019-01-09

·

Updated

2025-09-29

·

CVE-2016-10735

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bootstrap versions 2.0.4 through 3.x before 3.4.0 Bootstrap versions 4.x-beta before 4.0.0-beta.2
Description XSS is possible in the data-target attribute. This issue is different from other known vulnerabilities.
Recommendations For Bootstrap versions 2.0.4 through 3.x before 3.4.0, update to version 3.4.0 or later to resolve the issue. For Bootstrap versions 4.x-beta before 4.0.0-beta.2, update to version 4.0.0-beta.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the data-target attribute until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALSA-2020:4670
ALSA-2025_16880
CESA-2020_3936
CESA-2020_4670
CESA-2020_4847
CVE-2016-10735
GHSA-4P24-VMCR-4GQJ
RHSA-2019:3023
RHSA-2020:3936
RHSA-2020:4670
RHSA-2020:4847
RHSA-2020:5571
RHSA-2020_3936
RHSA-2020_4670
RHSA-2020_4847
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RLSA-2020:4670
RLSA-2020:4847

Affected Products

Almalinux
Bootstrap
Centos
Red Hat
Rocky Linux