Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34677
HistoryMar 14, 2022 - 11:40 a.m.

Cross-site Scripting (XSS)

2022-03-1411:40:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
cross-site scripting
xss
vulnerability
sanitization
iframe
cspservice.php
javascript

EPSS

0.001

Percentile

21.4%

ssddanbrown/bookstack, is vulnerable to cross-site scripting. The vulnerability exists due to the lack of sanitization of the iframe tags on the CspService.php file allows an attacker to inject javascript through it.

EPSS

0.001

Percentile

21.4%

Related for VERACODE:34677