Intel

AIKIDO-2025-10775

bootstrap is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-6485 Published Nov 6, 2025

62

Medium Risk

This Affects:

DOTNETbootstrap
1.4.0 - 3.4.1
Fixed in 5.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS): a flaw in the data-loading-text attribute of the Bootstrap button plugin (versions ≥ 1.4.0 to ≤ 3.4.1) allows malicious JavaScript to be injected and executed, for example when the button enters its loading state.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

bootstrap is vulnerable to Cross-site Scripting (XSS) in versions 1.4.0 - 3.4.1.

How to fix this

To fix this vulnerability, upgrade to a later, supported version of Bootstrap, as version 3 is end-of-life and no longer receives security updates.