Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35320
HistoryApr 29, 2022 - 4:16 a.m.

Cross-site Scripting (XSS)

2022-04-2904:16:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
facturascripts
plugin manager
ini parameter
xss
vulnerability
javascript
injection

EPSS

0.001

Percentile

21.4%

facturascripts/facturascripts is vulnerable to cross-site scripting. The vulnerability exists due to the lack of sanitization in the ini parameter in the getPluginInfo function of PluginManager.php, allowing an attacker to inject and execute malicious javascript

EPSS

0.001

Percentile

21.4%

Related for VERACODE:35320