Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21002
HistoryAug 06, 2019 - 6:34 a.m.

Information Disclosure

2019-08-0606:34:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.0004 Low

EPSS

Percentile

12.8%

grumpydictator/firefly-iii is vulnerable to information disclosure. The attack is due to lack of sanitization of fints_url parameter in the function configureJob, allowing an attacker to inject arbitrary script through it.

CPENameOperatorVersion
grumpydictator/firefly-iiile4.7.17.3

0.0004 Low

EPSS

Percentile

12.8%

Related for VERACODE:21002