Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34679
HistoryMar 14, 2022 - 1:51 p.m.

Improper Input Validation

2022-03-1413:51:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
improper input validation
url-js
parseurl function
host name spoofing

EPSS

0.001

Percentile

28.9%

url-js is vulnerable to improper input validation. The vulnerability exists in parseUrl function in parseUrl.js because the inputs are not parsed properly which allows an attacker to perform host name spoofing.

EPSS

0.001

Percentile

28.9%

Related for VERACODE:34679