CVE-2019-8331
MEDIUMBootstrap < 3.4.1 and 4.3.x < 4.3.1 - Cross-Site Scripting via Tooltip or Popover Data-Template Attribute
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2019-8331. PoCs published by Yumeae, Thampakon, Snorlyd.
AI-analyzed exploit summary This repository contains a static HTML file demonstrating multiple Bootstrap XSS vulnerabilities, including CVE-2019-8331, which exploits the Tooltip component's `data-template` attribute. It is designed for educational purposes and requires manual version switching to test different vulnerabilities.
Description
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Exploits (3)
This repository contains a static HTML file demonstrating multiple Bootstrap XSS vulnerabilities, including CVE-2019-8331, which exploits the Tooltip component's `data-template` attribute. It is designed for educational purposes and requires manual version switching to test different vulnerabilities.
The repository provides a description and examples of CVE-2019-8331, an XSS vulnerability in Bootstrap due to improper sanitization of data-template attributes in tooltip/popover elements. It includes PoC snippets demonstrating the exploit but lacks executable code.
This repository contains a writeup detailing CVE-2019-8331, an XSS vulnerability in Bootstrap versions prior to 3.4.1 and 4.3.1. The vulnerability arises from unsanitized input in the data-template, data-content, and data-title properties of tooltip/popover components.
References (27)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N