Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27559
HistoryOct 12, 2020 - 5:58 a.m.

Cross-site Scripting (XSS)

2020-10-1205:58:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.001

Percentile

29.2%

ActionPack is vulnerable to cross-site scripting (XSS). An attacker is able to embed a specially crafted URL via the location parameter in Actionable Exceptions middleware while the application server is in development mode, leading to the execution of malicious JavaScript in the context of the local application.