CVE-2016-10735

MEDIUM6.1EPSS 5.5%

Bootstrap Cross-site Scripting vulnerability

發布日:2019/1/17修改日:2026/4/28

描述

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

受影響套件(9)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

參考連結(19)