-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Package issue exists @ Npm-bootstrap-3.1.1 in branch main
In Bootstrap before 3.4.0 and 4.0.0 through 4.1.1, XSS is possible in the collapse data-parent attribute.
Namespace: CxDemoInABoxRepos
Repository: Java-Webgoat
Repository Url: https://github.com/CxDemoInABoxRepos/Java-Webgoat
CxAST-Project: CxDemoInABoxRepos/Java-Webgoat
CxAST platform scan: 54f047f8-7049-4205-83b9-9e21c75dc4c9
Branch: main
Application: Java-Webgoat
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-79
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 3.4.1
References
Advisory
Release Note
Mail Thread
Issue
Issue
Pull request
Commit
Commit