Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27616
HistoryOct 19, 2020 - 5:49 a.m.

Cross-Site Scripting (XSS)

2020-10-1905:49:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
matrix_synapse
xss attack
recaptcha
consent
single sign-on

EPSS

0.002

Percentile

53.0%

matrix_synapse is vulnerable to cross-site scripting (XSS). A attacker is able to inject and execute arbitrary Javascript in a user’s browser via the reCAPTCHA, consent (terms of service), or single sign-on functions.