Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20306
HistoryMay 22, 2019 - 11:22 a.m.

Cross-Site Scripting (XSS)

2019-05-2211:22:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

37.3%

IdentityServer4 is vulnerable to cross-site scripting (XSS) attacks. The vulnerability exists due to the lack of validations on httpContext parameter in the LogForErrorContext function in host/Extensions/RequestLoggerMiddleware.cs file, allowing remote attackers to inject and execute arbitrary JavaScript code in a victim’s browser.

EPSS

0.001

Percentile

37.3%

Related for VERACODE:20306