4 xss vulnerability dom based cwe 79 ; wordpress bootstrap.min.js is vulnerable
Medium
Vulnerability Details
## Summary:
I have found a bug in your site and the bug is xss vulnerability and it is in your wordpress bootstrap.min.js program. I also do manually test and I got the xss vulnearability
There are totally I have found 4 vulnearability in your system and which are belong to 2018
To 2019
## Steps To Reproduce:
1. Install retire.js extension in firefox browser
2. open your browser and redirect to your website . wait and check it gives you the full info
3. fuzz them by xss seclist directory it confirm the vulnerability
* [attachment / reference]
## Impact
A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired
Actions
View on HackerOneReport Stats
- Report ID: 1219002
- State: Closed
- Substate: duplicate
- Upvotes: 1