Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36686
HistoryAug 12, 2022 - 3:14 a.m.

Cross-site Scripting (XSS)

2022-08-1203:14:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
cross-site scripting
adaptiveimageservlet.java
svg image

EPSS

0.001

Percentile

25.3%

core.wcm.components.core is vulnerable to cross-site scripting. The vulnerability exists because the stream function of AdaptiveImageServlet.java does not properly encode the imageName attribute, allowing an attacker to inject and execute malicious javascript through the crafted SVG image.

EPSS

0.001

Percentile

25.3%