PT-2022-17960 · Bootstrap · Bootstrap

Published

2022-04-08

·

Updated

2022-04-22

·

CVE-2022-26624

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bootstrap versions 3.1.11 through 3.3.7
Description A cross-site scripting (XSS) issue was found in Bootstrap via the Title parameter in the "/vendor/views/add product.php" endpoint. This allows for potential XSS attacks.
Recommendations For Bootstrap versions 3.1.11 through 3.3.7, consider restricting access to the "/vendor/views/add product.php" endpoint until a fix is available, and avoid using the Title parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26624

Affected Products

Bootstrap