Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21000
HistoryAug 06, 2019 - 6:09 a.m.

Cross-site Scripting (XSS)

2019-08-0606:09:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.001 Low

EPSS

Percentile

21.4%

grumpydictator/firefly-iii is vulnerable to cross-site scripting (XSS). The attack is possible because it does not escape the user provided data in liability name field, allowing an attacker to inject malicious script in a transaction to get executed upon an error condition during a visit to the account show page.

CPENameOperatorVersion
grumpydictator/firefly-iiile4.7.17.5

0.001 Low

EPSS

Percentile

21.4%

Related for VERACODE:21000