Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23125
HistoryApr 10, 2020 - 12:16 a.m.

Cross-site Scripting (XSS)

2020-04-1000:16:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.061 Low

EPSS

Percentile

93.5%

httpd is vulnerable to cross-site scripting (XSS). The vulnerability exists as a flaw was found in the Apache HTTP Server mod_status module. On sites where the server-status page is publicly accessible and ExtendedStatus is enabled this could lead to a cross-site scripting attack. On Red Hat Enterprise Linux the server-status page is not enabled by default and it is best practice to not make this publicly available.

References