Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20561
HistoryJun 18, 2019 - 10:33 a.m.

Cross-site Scripting (XSS)

2019-06-1810:33:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

48.7%

concrete5/concrete5 is vulnerable to cross-site scripting attacks. The library does not sanitize imported SVG files, allowing a malicious user to inject and execute arbitrary web script into a victim’s browser.

CPENameOperatorVersion
concrete5/concrete5le8.4.5

0.001 Low

EPSS

Percentile

48.7%

Related for VERACODE:20561