Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21686
HistoryOct 11, 2019 - 8:20 a.m.

CSS Injection

2019-10-1108:20:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

EPSS

0.017

Percentile

88.0%

swagger-ui is vulnerable to CSS injection. The ?url= parameter allows an attacker to override a hard-coded schema file, which would enable for the Relative Path Overwrite (RPO) exploit technique, allowing exfiltration of confidential information from a victim’s browser such as the CSRF token value.

References