GHSA-vxmc-5x29-h64v

Suggest an improvement
Source
https://github.com/advisories/GHSA-vxmc-5x29-h64v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-vxmc-5x29-h64v/GHSA-vxmc-5x29-h64v.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-vxmc-5x29-h64v
Aliases
Published
2024-07-11T18:31:14Z
Modified
2024-11-19T00:12:21.218548Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
Details

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

Database specific
{
    "nvd_published_at": "2024-07-11T17:15:17Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-11-18T23:46:00Z"
}
References

Affected packages

npm / bootstrap

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.4.0
Fixed
3.4.1