Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35535
HistoryMay 14, 2022 - 11:45 p.m.

Cross-site Scripting (XSS)

2022-05-1423:45:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

34.8%

curl is vulnerable to cross-site scripting. The vulnerability exists due to the curl URL parser wrongly accepts percent-encoded URL separators like / when decoding the host name part of a URL which allows an attacker to inject and execute arbitrary javascript.