Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33537
HistoryJan 07, 2022 - 3:41 a.m.

Cross-site Scripting (XSS)

2022-01-0703:41:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
xss
cross-site scripting
confirmation.jspx
user input
malicious javascript
security vulnerability

EPSS

0.002

Percentile

57.4%

applicant-mvcbean-cdi-jsp-portlet is vulnerable to cross-site scripting. The library does not properly escape the user input parameters in confirmation.jspx, allowing an attacker to inject and execute malicious javascript.

EPSS

0.002

Percentile

57.4%

Related for VERACODE:33537