Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21004
HistoryAug 06, 2019 - 6:54 a.m.

Cross-site Scripting (XSS)

2019-08-0606:54:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

37.8%

grumpydictator/firefly-iii is vulnerable to cross-site scripting (XSS). The attack is possible because it does not escape the user provided data in transaction description field and in asset account name, allowing an attacker to inject malicious script in a convert transaction to get executed upon a user’s visit to the page.

CPENameOperatorVersion
grumpydictator/firefly-iiile4.7.17.3

0.001 Low

EPSS

Percentile

37.8%

Related for VERACODE:21004