Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37702
HistoryOct 27, 2022 - 6:16 a.m.

Cross-Site Scripting (XSS)

2022-10-2706:16:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
twisted
cross-site scripting
vulnerable
html
scripts
namevirtualhost

EPSS

0.002

Percentile

52.1%

twisted is vulnerable to cross-site scripting. The vulnerability is due to the function _getResourceForRequest in vhost.py. When the host header does not match the configured twisted.web.vhost.NameVirtualHost, the 404 page will render the header allowing an attacker to inject and execute HTML and scripts.