Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26988
HistorySep 21, 2020 - 6:29 a.m.

Cross-site Scripting (XSS)

2020-09-2106:29:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

45.2%

Activity Stream is vulnerable to cross-site scripting (XSS). It can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised.