Description
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
Remediation
References
Related Vulnerabilities
WordPress Plugin Twitter Button by BestWebSoft Cross-Site Request Forgery (2.14)
WordPress Plugin VideoWhisper Video Presentation 'c_status.php' SQL Injection (1.1)
WordPress Plugin Portfolio by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (2.27)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3743)