CVE-2024-6485

MEDIUM

Bootstrap 1.4.0-3.4.0 - Cross-Site Scripting via Button Plugin data-loading-text Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-6485. PoCs published by Yumeae.

AI-analyzed exploit summary This repository contains a static HTML file demonstrating multiple Bootstrap XSS vulnerabilities, including CVE-2019-8331, which exploits the Tooltip component's `data-template` attribute. It is designed for educational purposes and requires manual version switching to test different vulnerabilities.

Description

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

Exploits (1)

nomisec WORKING POC 3 stars
by Yumeae · poc
https://github.com/Yumeae/Bootstrap-with-XSS

This repository contains a static HTML file demonstrating multiple Bootstrap XSS vulnerabilities, including CVE-2019-8331, which exploits the Tooltip component's `data-template` attribute. It is designed for educational purposes and requires manual version switching to test different vulnerabilities.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Bootstrap v4.x < v4.3.1 and v3.x < v3.4.1
No auth needed
Prerequisites: A browser to open the HTML file · Manual editing of the HTML file to switch Bootstrap versions
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 6.4
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
Bootstrap/Bootstrap 1.4.0 - 3.4.1
Bootstrap-sass/bootstrap-sass 2.3.2 - 3.4.3
npm/bootstrap 1.4.0npm
Published Jul 11, 2024
Tracked Since Feb 18, 2026