4.3
CVSSv2

CVE-2018-14041

Published: 13/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Bootstrap prior to 4.1.2, XSS is possible in the data-target property of scrollspy.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getbootstrap bootstrap

getbootstrap bootstrap 4.0.0

Vendor Advisories

Debian Bug report logs - #907414 twitter-bootstrap3: CVE-2018-14040 CVE-2018-14041 CVE-2018-14042 Package: twitter-bootstrap3; Maintainer for twitter-bootstrap3 is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Antoine Beaupre <anarcat@debianorg> Date: Mon, 27 Aug 2018 18:3 ...
Synopsis Moderate: Red Hat Single Sign-On 732 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 73 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerab ...
Synopsis Moderate: Red Hat Ceph Storage 61 security, enhancement, and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Ceph Storage 61 in the Red HatEcosystem Catalog ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 749 Security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Enterprise Application Platform 74 for ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 749 Security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 74 Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syste ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> dotCMS v511 Vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: John Martinelli &lt;john () ...

Github Repositories

Vulnearability Report of the New Jersey official site

https-njgov---CVE-2018-14041 Vulnearability Report of the New Jersey official site The data-target attribute is vulnerable to Cross-Site Scripting attacks &lt;script src="ajaxgoogleapiscom/ajax/libs/jquery/224/jqueryminjs"&gt;&lt;/script&gt; &lt;script src="maxcdnbootstrapcdncom/bootstrap/336/js/bootstrapminjs"

Conversion tool for the biom format via php webservice

biom-conversion-server A simple php server that can convert biom version 2 (hdf5) files and data to biom version 1 (json) and vice versa It simply provides a web and API interface to the convert feature of the official python biom format tool This project is not part of the official biom project Please cite our article at f1000 Research that describes this module: Markus J

Vulnearability Report of the New Jersey official site

https-njgov---CVE-2018-14041 Vulnearability Report of the New Jersey official site The data-target attribute is vulnerable to Cross-Site Scripting attacks &lt;script src="ajaxgoogleapiscom/ajax/libs/jquery/224/jqueryminjs"&gt;&lt;/script&gt; &lt;script src="maxcdnbootstrapcdncom/bootstrap/336/js/bootstrapminjs"

repository for vulnerability check bootstrap: CVE-2018-14041 jQuery: CVE-2015-9251 prototypejs: CVE-2008-7220 and CVE-2007-2383 maybe GitHub can't detect prototypejs's vulnerabilities