Description
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Remediation
References
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6635)
WordPress Plugin Images Slideshow by 2J-Image Slider Unspecified Vulnerability (1.2.15)
WordPress Plugin Allow REL= and HTML in Author Bios Cross-Site Scripting (.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0216)