CVE-2016-10735

MEDIUM6.1EPSS 5.3%

Bootstrap Cross-site Scripting vulnerability

Published: 1/17/2019Modified: 2/4/2026
Also known as:GHSA-4p24-vmcr-4gqjCGA-6wg7-48v4-2pj7DEBIAN-CVE-2016-10735

Description

In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info.

Affected packages (9)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (19)