Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37233
HistorySep 22, 2022 - 5:01 a.m.

Stored Cross-site Scripting (XSS)

2022-09-2205:01:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
stored cross-site scripting
vulnerability
yetiforce/yetiforce-crm
widgetsmanagement

0.001 Low

EPSS

Percentile

21.6%

yetiforce/yetiforce-crm is vulnerable to stored cross-site scripting(XSS) attacks. The library does not properly escape the content of title parameter in WidgetsManagement module and it is used directly without any encoding or validation on ChartFilter.tpl, allowing an attacker to inject and execute malicious javascript to perform a stored XSS attack.

0.001 Low

EPSS

Percentile

21.6%

Related for VERACODE:37233