Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36056
HistoryJun 20, 2022 - 9:23 a.m.

Cross-site Scripting (XSS)

2022-06-2009:23:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
vulnerability
cross site scripting
input sanitization
renderer.php
malicious user
javascript
software

EPSS

0.001

Percentile

22.7%

brotkrueml/schema is vulnerable to cross site scripting. The vulnerability exists in the render function in Renderer.php due to a lack of sanitization in user input which allows a malicious backend user to inject and execute arbitrary javascript.

EPSS

0.001

Percentile

22.7%