CVE-2024-6485
XSS in Bootstrap button component
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
A vulnerability was found in bootstrap associated with the data-loading-text attribute within the button plugin. This vulnerability allows malicious JavaScript code to be injected into the attribute, which is then executed when the button's loading state is triggered.
It was discovered that Bootstrap did not correctly sanitize certain input in the carousel component. An attacker could possibly use this issue to execute a cross-site scripting attack. It was discovered that Bootstrap did not correctly sanitize certain input in the button plugin. An attacker could possibly use this issue to execute a cross-site scripting attack.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-07-03 CVE Reserved
- 2024-07-11 CVE Published
- 2025-02-24 CVE Updated
- 2025-07-21 First Exploit
- 2025-08-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
- CAPEC-63: Cross-Site Scripting (XSS)
References (4)
URL | Date | SRC |
---|---|---|
https://github.com/Yumeae/Bootstrap-with-XSS | 2025-07-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-6485 | 2025-02-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2297388 | 2025-02-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bootstrap Search vendor "Bootstrap" | Bootstrap Search vendor "Bootstrap" for product "Bootstrap" | >= 1.4.0 <= 3.4.1 Search vendor "Bootstrap" for product "Bootstrap" and version " >= 1.4.0 <= 3.4.1" | en |
Affected
| ||||||
Bootstrap-sass Search vendor "Bootstrap-sass" | Bootstrap-sass Search vendor "Bootstrap-sass" for product "Bootstrap-sass" | >= 2.3.2 <= 3.4.3 Search vendor "Bootstrap-sass" for product "Bootstrap-sass" and version " >= 2.3.2 <= 3.4.3" | en |
Affected
|