Back

MEDIUM

XSS in Bootstrap button component

Published Jul 11, 2024

Description

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HeroDevs
Published Jul 11, 2024
Updated Nov 3, 2025
Reserved Jul 3, 2024
CISA Vulnrichment
Updated Jul 11, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 11, 2024
ENISA EUVD
Assigner HeroDevs
Published Jul 11, 2024
Updated Nov 3, 2025
Exploited since n/a
EUVD-2024-2429 GHSA-VXMC-5X29-H64V