PT-2024-37693 · Bootstrap+3 · Bootstrap+3

K

·

Published

2024-07-11

·

Updated

2026-01-03

·

CVE-2024-6531

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Bootstrap (affected versions not specified)
Description A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an tag due to inadequate sanitization. This could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6531
DLA-4125-1
GHSA-VC8W-JR9V-VJ7F
USN-7556-1

Affected Products

Bootstrap
Debian
Linuxmint
Ubuntu