DRUPAL-CONTRIB-2018-074

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2018-074

    DRUPAL-CONTRIB-2018-074

    Published: 28 Nov 2018Last Modified: 10 Sept 2026

    Summary:

    Details: This base theme bridges the gap between Drupal and the Bootstrap Framework. The theme doesn't sufficiently filter valid targets under the scenario of opening modals, popovers, and tooltips. This vulnerability is mitigated by the fact that an attacker must already have the ability to either: 1. Edit/save custom content that supplies a value for the `data-target` attribute by injecting malicious code. 2. Inject custom markup onto the page that further exploits the `data-target` attribute by injecting malicious code. This method of attack is highly unlikely if they already have this level of access. Note: while the base-theme does not provide either of these opportunities to do this out-of-the-box; a custom sub-theme may, however, be susceptible if it didn't sanitize or filter user provided input for XSS properly.

    Affected packages

    Package

    Name: drupal/bootstrap

    Purl: pkg:composer/drupal/bootstrap?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.14.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High