Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32890
HistoryNov 10, 2021 - 5:10 a.m.

Cross-site Scripting (XSS)

2021-11-1005:10:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
cross-site scripting
vulnerability
sanitization
javascript
injection

EPSS

0.001

Percentile

32.7%

graphql-playground-react is vulnerable to cross-site scripting. The vulnerability exists due to the lack of sanitization in onHasCompletion.js allowing an attacker to inject and execute malicious javascript.

EPSS

0.001

Percentile

32.7%

Related for VERACODE:32890