CVE-2018-14040

Updated on 13 Jul 2018

Severity

6.1 Medium severity

Details

CVSS score
6.1
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Overview

About vulnerability

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Details

Affected product:
Bootstrap
Affected packages:
bootstrap @ 3.2.0 (+2 more)
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Fixes