Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13403
HistoryMar 05, 2019 - 8:25 a.m.

Cross-Site Scripting (XSS)

2019-03-0508:25:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

EPSS

0.002

Percentile

58.9%

bolt/bolt is vulnerable to cross-site scripting (XSS). A remote attacker is able to inject arbitrary Javascript into a victim’s browser via the title and slug parameters in a POST request to /bolt/editcontent/pages

EPSS

0.002

Percentile

58.9%