Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38807
HistoryJan 10, 2023 - 2:36 a.m.

Cross-site Scripting (XSS)

2023-01-1002:36:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
cross-site scripting
org.apache.sling.cms.ui
javascriptinjection
sitegroupfeature
securityvulnerability
software

0.001 Low

EPSS

Percentile

38.4%

org.apache.sling.cms.ui is vulnerable to Cross-site Scripting (XSS). The vulnerability exists because the library does not properly encode the resource.path variable before being rendered, allowing an attacker to inject and execute malicious JavaScript through the site group feature.

0.001 Low

EPSS

Percentile

38.4%

Related for VERACODE:38807