Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32919
HistoryNov 11, 2021 - 10:52 a.m.

Cross-site Scripting (XSS)

2021-11-1110:52:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
cross-site scripting
publify
vulnerability
file types
attacker
javascript

EPSS

0.001

Percentile

19.4%

publify is vulnerable to cross-site scripting attacks. The vulnerability exists because it doesn’t check limit the file types that can be uploaded in resource_uploader.rb which allows an attacker to inject and execute arbitrary javascript via uploaded html files.

EPSS

0.001

Percentile

19.4%