Description
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2910 Vulnerability (CVE-2019-2910)
WordPress Plugin WP-StarsRateBox 'j' Parameter SQL Injection (1.1)
Drupal Core 9.2.x Multiple Security Bypass Vulnerabilities (9.2.0 - 9.2.5)
WordPress Plugin WooCommerce Product Attachment Cross-Site Scripting (1.1.2)
WordPress Plugin Access Expiration Cross-Site Scripting (1.1)