PT-2025-21333 · Bootstrap+2 · Bootstrap+2

Johan Carlsson

·

Published

2025-05-15

·

Updated

2026-04-03

·

CVE-2025-1647

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Bootstrap versions 3.4.1 through 3.4.x
Description: The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows attackers to run malicious scripts. A DOM-based XSS flaw was found in Bootstrap 3 Tooltips & Popovers, which can be exploited via DOM clobbering, putting outdated applications at risk.
Recommendations: For Bootstrap versions 3.4.1 through 3.4.x, update to version 4.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of Bootstrap 3 Tooltips & Popovers until a patch is available. Restrict access to potentially vulnerable web pages to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-1647
DLA-4204-1
GHSA-Q58R-HWC8-RM9J

Affected Products

Astra Linux
Bootstrap
Debian