In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| bootstrap(npm) | 0 | 3.4.0 | N/A |
| bootstrap-sass(npm) | 0 | 3.4.0 | N/A |
| twbs/bootstrap(Packagist) | 0 | 3.4.0 | N/A |
| org.webjars:bootstrap(Maven) | 0 | 3.4.0 | N/A |
| bootstrap(RubyGems) | 0 | 3.4.0 | N/A |
| bootstrap-sass(RubyGems) | 0 | 3.4.0 | N/A |
| bootstrap(NuGet) | 0 | 3.4.0 | N/A |
CVSS Metrics