Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32471
HistoryOct 13, 2021 - 3:45 a.m.

Cross-Site Scripting (XSS)

2021-10-1303:45:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
cross-site scripting
vulnerability
custom urls
'buildform' function
malicious attacker
arbitrary scripts
prestashop

EPSS

0.001

Percentile

19.4%

prestashop/ps_linklist is vulnerable to cross-site scripting. The vulnerability exists because the custom URLs are not validated in ‘buildForm’ function in ‘CustomUrlType.php’ allowing a malicious attacker to inject arbitrary scripts.

EPSS

0.001

Percentile

19.4%

Related for VERACODE:32471