Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38870
HistoryJan 15, 2023 - 9:36 p.m.

Cross-site Scripting (XSS)

2023-01-1521:36:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
cross-site scripting
django_ucamlookup
searchable dropdowns
malicious javascript
lookup handler

EPSS

0.001

Percentile

34.3%

django_ucamlookup is vulnerable to Cross-Site Scripting (XSS) attacks. The invocation of jquery select2 to provide searchable dropdowns does not sanitize data coming from the lookup, allowing an attacker to inject and execute malicious JavaScript through formatResult function of the component Lookup Handler.

EPSS

0.001

Percentile

34.3%

Related for VERACODE:38870