Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33556
HistoryJan 07, 2022 - 10:36 a.m.

Cross-site Scripting (XSS)

2022-01-0710:36:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
cross-site scripting
apache portals pluto
demo portal
user input
remote attacker
malicious javascript
vulnerable software

EPSS

0.002

Percentile

57.4%

org.apache.portals.pluto.demo:v3-demo-portlet is vulnerable to cross-site scripting (XSS). The library does not properly escape the user input parameters in UrlTestPortlet, allowing a remote attacker to inject and execute malicious javascript.

EPSS

0.002

Percentile

57.4%

Related for VERACODE:33556