Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36146
HistoryJun 27, 2022 - 6:39 a.m.

Cross-site Scripting (XSS)

2022-06-2706:39:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

36.7%

concrete5/concrete5 is vulnerable to cross-site scripting. The vulnerability exists due to the insufficient sanitization in the input urls, allowing an attacker to inject and execute malicious javascript when using an older browser with built-in XSS protection is disabled.

0.001 Low

EPSS

Percentile

36.7%

Related for VERACODE:36146