Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37125
HistorySep 19, 2022 - 6:32 a.m.

Cross Site Scripting (XSS)

2022-09-1906:32:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
cross site scripting
craft cms
addresscardhtml
javascript
vulnerability

EPSS

0.001

Percentile

21.4%

craftcms/cms is vulnerable to cross-site scripting(XSS) attacks. The library does not properly escape user inputs through title parameter in addressCardHtml function, which allows an attacker to inject and execute malicious javascript on victim’s browser.

EPSS

0.001

Percentile

21.4%

Related for VERACODE:37125