CVE-2018-14041: XSS
A flaw was found in Bootstrap from version 4.0 and before 4.1.2. A Cross-site Scripting (XSS) is possible in the data-target property of scrollspy.
References: https://github.com/twbs/bootstrap/issues/26627
Upstream Patch: https://github.com/twbs/bootstrap/pull/26630
Other sources
A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting, caused by improper validation of user-supplied input by the data-target property of scrollspy. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting Web site, which can lead to stealing the victim's cookie-based authentication credentials.
Bootstrap is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the data-target property of scrollspy. A remote attacker could exploit this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
— IBM
Cross-Site Scripting in Bootstrap CSS toolkit
In Bootstrap 4.x before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.
— GitHub
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this cross-site scripting vulnerability in Bootstrap CSS toolkit?
The vulnerability ID is CVE-2018-14041.
What is the severity of CVE-2018-14041?
The severity of CVE-2018-14041 is medium (6.1).
Which software versions are affected by CVE-2018-14041?
The affected software versions are TYPO3 CMS versions 8.0.0 to 8.7.23 and 9.0.0 to 9.5.4, and Red Hat EAP7 HAL Console versions 0:3.3.16-1.Final_redhat_00001.1.el8ea, 0:3.3.16-1.Final_redhat_00001.1.el9ea, and 0:3.3.16-1.Final_redhat_00001.1.el7ea.
How does this vulnerability in Bootstrap CSS toolkit affect the user?
This vulnerability allows a remote attacker to execute scripts in a victim's web browser within the security context of the hosting website.
How can I mitigate the cross-site scripting vulnerability in Bootstrap CSS toolkit?
To mitigate this vulnerability, update to TYPO3 CMS versions 8.7.24 or 9.5.5, or apply the appropriate patch provided by Red Hat for EAP7 HAL Console.