CVE-2019-8331

MEDIUM

Bootstrap < 3.4.1 - XSS

Title source: rule

Description

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

Exploits (3)

nomisec WORKING POC 3 stars
by Yumeae · poc
https://github.com/Yumeae/Bootstrap-with-XSS
nomisec WRITEUP
by Thampakon · poc
https://github.com/Thampakon/CVE-2019-8331
nomisec WRITEUP
by Snorlyd · poc
https://github.com/Snorlyd/https-nj.gov---CVE-2019-8331

References (27)

... and 7 more

Scores

CVSS v3 6.1
EPSS 0.0167
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (26)

getbootstrap/bootstrap < 3.4.1
f5/big-ip_access_policy_manager < 12.1.5.1
f5/big-ip_advanced_firewall_manager < 12.1.5.1
f5/big-ip_analytics < 12.1.5.1
f5/big-ip_application_acceleration_manager < 12.1.5.1
f5/big-ip_application_security_manager < 12.1.5.1
f5/big-ip_domain_name_system < 12.1.5.1
f5/big-ip_edge_gateway < 12.1.5.1
f5/big-ip_fraud_protection_service < 12.1.5.1
f5/big-ip_global_traffic_manager < 12.1.5.1
f5/big-ip_link_controller < 12.1.5.1
f5/big-ip_local_traffic_manager < 12.1.5.1
f5/big-ip_policy_enforcement_manager < 12.1.5.1
f5/big-ip_webaccelerator < 12.1.5.1
redhat/virtualization_manager
... and 11 more

Timeline

Published Feb 20, 2019
Tracked Since Feb 18, 2026