A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade twitter-bootstrap3 | Apr 14, 2025 | Jul 11, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 11, 2024 |
| Ubuntu | — | Upgrade libjs-bootstrapUpgrade libjs-bootstrap4 (Ubuntu Pro)Upgrade libjs-bootstrap (Ubuntu Pro)Upgrade libjs-bootstrap4 | Jun 6, 2025 | Jul 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub