[Bug]: nextcloud acunetix scan is showing bootstrap version 3.3.5 is vulnerable to cross site scripting attacks. #43893
Labels
0. Needs triage
Pending check for reproducibility or if it fits our roadmap
27-feedback
bug
feature: files
needs info
security
Bug description
Bootstrap Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vulnerability. In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
References
CVE-2018-14040,CVE-2018-20677,CVE-2018-14042,CVE-2018-20676 & CVE-2019-8331
Steps to reproduce
Expected behavior
acunetix scan should report latest bootstrap version
Installation method
Community Manual installation with Archive
Nextcloud Server version
27
Operating system
Debian/Ubuntu
PHP engine version
PHP 8.1
Web server
Apache (supported)
Database engine version
MariaDB
Is this bug present after an update or on a fresh install?
Fresh Nextcloud Server install
Are you using the Nextcloud Server Encryption module?
None
What user-backends are you using?
Configuration report
No response
List of activated Apps
No response
Nextcloud Signing status
No response
Nextcloud Logs
No response
Additional info
No response
The text was updated successfully, but these errors were encountered: