CVE-2019-8331

MEDIUM

Bootstrap < 3.4.1 - XSS

Title source: rule

Description

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

Exploits (3)

nomisec WORKING POC 3 stars
by Yumeae · poc
https://github.com/Yumeae/Bootstrap-with-XSS
nomisec WRITEUP
by Thampakon · poc
https://github.com/Thampakon/CVE-2019-8331
nomisec WRITEUP
by Snorlyd · poc
https://github.com/Snorlyd/https-nj.gov---CVE-2019-8331

References (27)

... and 7 more

Scores

CVSS v3 6.1
EPSS 0.0171
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (26)
f5/big-ip_access_policy_manager 12.1.0 - 12.1.5.1
f5/big-ip_advanced_firewall_manager 12.1.0 - 12.1.5.1
f5/big-ip_analytics 12.1.0 - 12.1.5.1
f5/big-ip_application_acceleration_manager 12.1.0 - 12.1.5.1
f5/big-ip_application_security_manager 12.1.0 - 12.1.5.1
f5/big-ip_domain_name_system 12.1.0 - 12.1.5.1
f5/big-ip_edge_gateway 12.1.0 - 12.1.5.1
f5/big-ip_fraud_protection_service 12.1.0 - 12.1.5.1
f5/big-ip_global_traffic_manager 12.1.0 - 12.1.5.1
f5/big-ip_link_controller 12.1.0 - 12.1.5.1
... and 16 more
Published Feb 20, 2019
Tracked Since Feb 18, 2026