VDB

DEBIAN-CVE-2024-6485

DEBIAN-CVE-2024-6485 PUBLISHED CVSS 6.400000095367432 MEDIUM

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

Risk Scores

CVSS 3.1
6.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

Affected Products

VendorProductVersions
Debian:14twitter-bootstrap30, 0
Debian:12twitter-bootstrap30, 3.4.1+dfsg-3, 0
Debian:13twitter-bootstrap30, 0
Debian:11twitter-bootstrap30, *, 0

Timeline

  • Jul 11, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›