Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34552
HistoryMar 07, 2022 - 10:08 a.m.

Cross-site Scripting (XSS)

2022-03-0710:08:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.001 Low

EPSS

Percentile

49.6%

Liferay Frontend Taglib Clay is vulnerable to cross-site scripting. The vulnerability exists in processStartTag function of ManagementToolbarTag.java because the keyword in the search function is not escaped which allows an attacker to inject and execute arbitrary javascript.

0.001 Low

EPSS

Percentile

49.6%

Related for VERACODE:34552