Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38466
HistoryDec 14, 2022 - 4:47 a.m.

Cross-Site Scripting (XSS)

2022-12-1404:47:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
loofah
xss
vulnerability
data url
sanitization
software
remote attacker
javascript

0.001 Low

EPSS

Percentile

50.9%

loofah is vulnerable to cross-site scripting. The vulnerability exists due to the lack of sanitization data urls in the image/svg+xml parameter in safelist.rb which allows a remote attacker to inject and execute malicious JavaScript into the system.