Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36841
HistoryAug 30, 2022 - 4:01 a.m.

Cross-site Scripting (XSS)

2022-08-3004:01:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
getkirby/cms
cross-site scripting
v-html tag
multiselectinput.vue
dynamic options
multi-select field
malicious javascript
vulnerability

EPSS

0.001

Percentile

32.3%

getkirby/cms is vulnerable to Cross-site Scripting (XSS). The use of the v-html tag in MultiselectInput.vue allows an attacker to inject and execute malicious javascript through the dynamic options in the multi-select field

EPSS

0.001

Percentile

32.3%

Related for VERACODE:36841