Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36059
HistoryJun 20, 2022 - 12:10 p.m.

Cross-Site Scripting (XSS)

2022-06-2012:10:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
cross-site scripting
matomo
psr-14 events
arbitrary javascript

EPSS

0.001

Percentile

31.3%

brotkrueml/typo3-matomo-integration is vulnerable to cross-site scripting. The vulnerability exists in convertStringValue function in MatomoMethodCall.php because the content from PSR-14 events are not properly escaped which allows an attackers to inject and execute arbitrary javascript.

EPSS

0.001

Percentile

31.3%