Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38335
HistoryDec 05, 2022 - 5:27 a.m.

Cross-site Scripting (XSS)

2022-12-0505:27:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
cross-site scripting
nextcloud-desktop
applicationwindow
window.qml
javascript
vulnerability

EPSS

0.001

Percentile

26.4%

nextcloud-desktop is vulnerable to cross-site scripting. The vulnerability exists in ApplicationWindow function of Window.qml due to incorrectly neutralizes user-controllable input which allows an attacker to inject and execute malicious JavaScript.