Description
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Remediation
References
Related Vulnerabilities
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38844)
WordPress Plugin WordPress Calls to Action Unspecified Vulnerability (2.3.1)
WordPress Plugin Cool Timeline (Horizontal & Vertical Timeline) Security Bypass (2.3.3)
Oracle JRE Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0422)