Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21001
HistoryAug 06, 2019 - 6:23 a.m.

Cross-site Scripting (XSS)

2019-08-0606:23:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

21.4%

grumpydictator/firefly-iii is vulnerable to cross-site scripting (XSS). The attack is possible because it does not escape the user provided data increate-from-bill name field, allowing an attacker to inject malicious script.

CPENameOperatorVersion
grumpydictator/firefly-iiile4.7.17.3

0.001 Low

EPSS

Percentile

21.4%

Related for VERACODE:21001