Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20548
HistoryJun 17, 2019 - 12:21 a.m.

Cross-site Scripting (XSS)

2019-06-1700:21:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

21.9%

picketlink is vulnerable to cross-site scripting. A remote attacker is able to inject arbitrary Javascript into a victim’s browser through an SAMLRequest via the RelayState parameter.

References

0.001 Low

EPSS

Percentile

21.9%