Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29840
HistoryMar 27, 2021 - 10:52 p.m.

HTML Injection

2021-03-2722:52:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
matrix-synapse
html injection
notification emails
user's browser
software vulnerability

EPSS

0.001

Percentile

44.0%

matrix-synapse is vulnerable to HTML injection. Lack of output sanitization of the notification emails that are sent for notifications for missed messages or for an expiring account allows an attacker to inject and execute arbitrary HTML code in a user’s browser.

EPSS

0.001

Percentile

44.0%