Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23983
HistoryApr 10, 2020 - 12:42 a.m.

Cross-Site Scripting (XSS)

2020-04-1000:42:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.02

Percentile

88.9%

php is vulnerable to cross-site scripting (XSS). It was discovered that PHP’s htmlspecialchars() function did not properly recognize partial multi-byte sequences for some multi-byte encodings, sending them to output without them being escaped. An attacker could use this flaw to perform a cross-site scripting attack.