Loading HuntDB...

4 xss vulnerability dom based cwe 79 ; wordpress bootstrap.min.js is vulnerable

Medium
S
Sifchain
Submitted None
Reported by rao_ji1hackerone

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - DOM
## Summary: I have found a bug in your site and the bug is xss vulnerability and it is in your wordpress bootstrap.min.js program. I also do manually test and I got the xss vulnearability There are totally I have found 4 vulnearability in your system and which are belong to 2018 To 2019 ## Steps To Reproduce: 1. Install retire.js extension in firefox browser 2. open your browser and redirect to your website . wait and check it gives you the full info 3. fuzz them by xss seclist directory it confirm the vulnerability * [attachment / reference] ## Impact A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted

Weakness

Cross-site Scripting (XSS) - DOM