Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38564
HistoryDec 22, 2022 - 6:58 a.m.

Cross-Site Scripting (XSS)

2022-12-2206:58:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
cross-site scripting
vulnerability
javascript injection
user input sanitization

0.001 Low

EPSS

Percentile

46.7%

smoothie is vulnerable to cross-site scripting. The vulnerability exists in multiple functions in smoothie.js because user inputs are not properly sanitized which allows an attacker to inject and execute arbitrary JavaScript.

0.001 Low

EPSS

Percentile

46.7%

Related for VERACODE:38564