Description
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Remediation
References
Related Vulnerabilities
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.4.1)
WordPress Plugin WP-Ban Security Bypass (1.63)
WordPress Plugin BuddyPress Cross-Site Scripting (2.2.2.1)
SharePoint CVE-2020-0977 Vulnerability (CVE-2020-0977)
Elgg Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6563)