Bootstrap security update to version 5 (MINDBREEZE32146)
ID: MINDBREEZE32146
Affected Components: Mindbreeze InSpire
Severity: Medium 6.4
Status: Final
First published: October 10, 2024
CVEs: CVE-2024-6484, CVE-2024-6531
Summary
- A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an <a> tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 24.6 Release
- Mindbreeze InSpire SaaS 24.6 Release