Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21003
HistoryAug 06, 2019 - 6:44 a.m.

Cross-site Scripting (XSS)

2019-08-0606:44:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

21.4%

grumpydictator/firefly-iii is vulnerable to cross-site scripting (XSS). The attack is possible because it does not escape the user provided data in the asset account name field, allowing an attacker to inject malicious script through it.

CPENameOperatorVersion
grumpydictator/firefly-iiile4.7.17.3

0.001 Low

EPSS

Percentile

21.4%

Related for VERACODE:21003