VYPR
Medium severity6.1NVD Advisory· Published Jul 13, 2018· Updated Jun 17, 2026

CVE-2018-14041

CVE-2018-14041

Description

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
bootstrapnpm
>= 4.0.0, < 4.1.24.1.2
typo3/cms-corePackagist
>= 8.0.0, < 8.7.238.7.23
typo3/cms-corePackagist
>= 9.0.0, < 9.5.49.5.4
typo3/cmsPackagist
>= 8.0.0, < 8.7.238.7.23
typo3/cmsPackagist
>= 9.0.0, < 9.5.49.5.4
bootstrapRubyGems
>= 4.0.0, < 4.1.24.1.2
twbs/bootstrapPackagist
>= 4.0.0, < 4.1.24.1.2
bootstrapNuGet
>= 4.0.0, < 4.1.24.1.2
bootstrap.sassNuGet
>= 4.0.0, < 4.1.24.1.2
org.webjars:bootstrapMaven
>= 4.0.0, < 4.1.24.1.2

Affected products

18
  • cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:*range: >=4.0.0,<4.1.2
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha6:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:getbootstrap:bootstrap:4.0.0:beta:*:*:*:*:*:*
  • ghsa-coords8 versions
    >= 4.0.0, < 4.1.2+ 7 more
    • (no CPE)range: >= 4.0.0, < 4.1.2
    • (no CPE)range: >= 8.0.0, < 8.7.23
    • (no CPE)range: >= 8.0.0, < 8.7.23
    • (no CPE)range: >= 4.0.0, < 4.1.2
    • (no CPE)range: >= 4.0.0, < 4.1.2
    • (no CPE)range: >= 4.0.0, < 4.1.2
    • (no CPE)range: >= 4.0.0, < 4.1.2
    • (no CPE)range: >= 4.0.0, < 4.1.2

Patches

Vulnerability mechanics

References

29

News mentions

0

No linked articles in our index yet.