4 xss vulnerability dom based cwe 79 ; wordpress bootstrap.min.js is vulnerable
Medium
S
Sifchain
Submitted None
Actions:
Reported by
rao_ji1hackerone
Vulnerability Details
Technical details and impact analysis
## Summary:
I have found a bug in your site and the bug is xss vulnerability and it is in your wordpress bootstrap.min.js program. I also do manually test and I got the xss vulnearability
There are totally I have found 4 vulnearability in your system and which are belong to 2018
To 2019
## Steps To Reproduce:
1. Install retire.js extension in firefox browser
2. open your browser and redirect to your website . wait and check it gives you the full info
3. fuzz them by xss seclist directory it confirm the vulnerability
* [attachment / reference]
## Impact
A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate
Submitted
Weakness
Cross-site Scripting (XSS) - DOM