Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33966
HistoryJan 31, 2022 - 7:03 a.m.

Cross-site Scripting (XSS)

2022-01-3107:03:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
laminas-form
xss
validation error
javascript
remote attacker

EPSS

0.002

Percentile

60.0%

laminas/laminas-form is vulnerable to cross-site scripting (XSS) attacks. A remote unauthenticated attacker is able to inject and execute malicious javascript on victim’s browser through the unescaped submitted values when rendering validation error messages via the formElementErrors function.

EPSS

0.002

Percentile

60.0%