Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21596
HistoryOct 01, 2019 - 2:34 a.m.

Cross-Site Scripting (XSS)

2019-10-0102:34:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.004 Low

EPSS

Percentile

72.1%

no-vnc is vulnerable to cross-site scripting (XSS). A remote attacker is able to inject arbitrary Javascript ito a victim’s browser via messages propagated to the status field such as the VNC server name.