Bootstrap security update to version 5 (MINDBREEZE32146)

ID: MINDBREEZE32146
Affected Components: Mindbreeze InSpire  
Severity: Medium 6.4 
Status: Final 
First published: October 10, 2024   
CVEs: CVE-2024-6484, CVE-2024-6531 

Summary

  • A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an <a> tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 24.6 Release 
  • Mindbreeze InSpire SaaS 24.6 Release