Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25622
HistoryJun 08, 2020 - 3:03 a.m.

Cross-site Scripting (XSS)

2020-06-0803:03:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.001

Percentile

22.7%

verbb/comments is vulnerable to cross-site scripting (XSS). It is possible because it does not sanitize the user-provided input for guest name username, allowing an attacker to inject and execute malicious scripts in a user’s browser.

EPSS

0.001

Percentile

22.7%

Related for VERACODE:25622