Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35164
HistoryApr 19, 2022 - 11:13 a.m.

Cross-site Scripting (XSS)

2022-04-1911:13:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

51.9%

net.sourceforge.plantuml:plantuml is vulnerable to cross-site scripting(XSS) attacks. The library allows SVG markup to get inserted directly into the markup of an enclosing SVG, making it possible to inject specifically crafted malicious SVG files and execute dangerous payloads inside the targeted system.