Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36139
HistoryJun 27, 2022 - 5:27 a.m.

Cross-site Scripting (XSS)

2022-06-2705:27:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

36.7%

concrete5/concrete5 is vulnerable to cross-site scripting. The vulnerability exists in the old browsers with the XSS protection is disabled, allowing an attacker to inject and execute malicious javascript as the library does not properly escape malicious inputs by default.

0.001 Low

EPSS

Percentile

36.7%

Related for VERACODE:36139