A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an <a> tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.
https://www.herodevs.com/vulnerability-directory/cve-2024-6531
https://lists.debian.org/debian-lts-announce/2025/04/msg00021.html
Published: 2024-07-11
Updated: 2025-04-13
Base Score: 6.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:P/A:P
Severity: Medium
Base Score: 6.4
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Severity: Medium
Base Score: 5.3
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L
Severity: Medium
EPSS: 0.00201