CVE-2018-14041

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

  • Published Jul 13, 2018
  • CVSS 6.1 medium
  • 4.3% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available
  • A fix is available

In the news

CVE-2018-14041 at the National Vulnerability Database