Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36542
HistoryAug 01, 2022 - 3:39 a.m.

Cross-site Scripting (XSS)

2022-08-0103:39:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
cross-site scripting
velociraptor
vulnerability
javascript injection
artifact collection

EPSS

0.001

Percentile

31.3%

github.com/velocidex/velociraptor is vulnerable to cross-site scripting. The vulnerability exists in multiple functions in artifacts/syntax.js because the variables are not properly escaped in artifact collection report which allows an attacker to inject and execute malicious javascript.

EPSS

0.001

Percentile

31.3%

Related for VERACODE:36542