Security Games Windows Linux Android IOS News Reviews AI

CVE-2024-6531 Vulnerability Details

  /     /     /  

CVE-2024-6531 Metadata Quick Info

CVE Published: 11/07/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: HeroDevs | Vendor: Bootstrap | Product: Bootstrap
Status : PUBLISHED

CVE-2024-6531 Description

A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim\'s browser.

Metrics

CVSS Version: 3.1 | Base Score: 6.4 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* LOW
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-79
CWE Name: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or Cross-site Scripting )
Source: Bootstrap

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-63
CAPEC Description: CAPEC-63 Cross-Site Scripting (XSS)


Source: NVD (National Vulnerability Database).

Last added CVEs

▸ CVE-2024-9999 ◂
Discovered: 12/11/2024
Status: PUBLISHED

▸ CVE-2024-9997 ◂
Discovered: 29/10/2024
Status: PUBLISHED

▸ CVE-2024-9996 ◂
Discovered: 29/10/2024
Status: PUBLISHED



Tags:
CVE-2024-6531 Vulnerability Details


Free Software Downloads, News and Reviews
Info
Legal
  • GDPR
  • Contact
  • ToS
  • Sitemap
Partners
  • Curs-cybersecurity.ro
Last News
  • 01/07/2025 ArcSight prepares for ...
  • 01/07/2025 Samsung Epic 4G: ...
  • 01/07/2025 Many third-party software ...
facebook twitter youtube linkedin

Copyright © 2025 Free Downloads Now