In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
2019-02-20T16:29:00.837
2024-11-21T04:49:42.020
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | getbootstrap | bootstrap | < 3.4.1 | Yes |
| Application | getbootstrap | bootstrap | < 4.3.1 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_analytics | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_analytics | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_analytics | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_analytics | < 15.1.0 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_application_security_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_application_security_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_application_security_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_application_security_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_domain_name_system | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_domain_name_system | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_domain_name_system | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_domain_name_system | < 15.1.0 | Yes |
| Application | f5 | big-ip_edge_gateway | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_edge_gateway | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_edge_gateway | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_edge_gateway | < 15.1.0 | Yes |
| Application | f5 | big-ip_fraud_protection_service | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_fraud_protection_service | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_fraud_protection_service | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_fraud_protection_service | < 15.1.0 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_link_controller | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_link_controller | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_link_controller | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_link_controller | < 15.1.0 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_webaccelerator | < 12.1.5.1 | Yes |
| Application | f5 | big-ip_webaccelerator | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_webaccelerator | < 14.1.2.5 | Yes |
| Application | f5 | big-ip_webaccelerator | < 15.1.0 | Yes |
| Application | redhat | virtualization_manager | 4.3 | Yes |
| Application | tenable | tenable.sc | < 5.19.0 | Yes |