Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34510
HistoryMar 04, 2022 - 11:41 a.m.

Cross-site Scripting (XSS)

2022-03-0411:41:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
31

0.001 Low

EPSS

Percentile

29.2%

com.liferay:com.liferay.layout.admin.web is vulnerable to cross-site scripting. The library does not properly escape the COLLECTION_NAME parameter before it output to the front end, allowing an attacker to inject and execute malicious javascript.

0.001 Low

EPSS

Percentile

29.2%

Related for VERACODE:34510