Description In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. Remediation References CVE-2018-14041 Related Vulnerabilities WordPress Plugin Request Quote via Whatsapp for Woocommerce Cross-Site Scripting (1.0.1) WordPress Plugin WP YouTube Live Cross-Site Scripting (1.7.21) Oracle Database Server CVE-2010-0901 Vulnerability (CVE-2010-0901) Lighttpd Other Vulnerability (CVE-2007-3947) WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.34) Severity Medium Classification CVE-2018-14041 CWE-707 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities