Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20849
HistoryJul 18, 2019 - 5:59 a.m.

Cross-site Scripting (XSS)

2019-07-1805:59:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

EPSS

0.001

Percentile

21.4%

grumpydictator/firefly-iii is vulnerable to cross-site scripting (XSS). The attack is possible because it does not escape the user provided data in budget name, allowing an attacker to inject malicious script in a transaction to get executed on the tags/show/$tag_number$ tag summary page.

EPSS

0.001

Percentile

21.4%