Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38900
HistoryJan 18, 2023 - 1:39 a.m.

Cross-site Scripting (XSS)

2023-01-1801:39:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
cross-site scripting
apache_superset
upload data forms
authenticated attacker
javascript

EPSS

0.001

Percentile

32.6%

apache_superset is vulnerable to Cross-Site Scripting (XSS) attacks. The library does not properly render user inputs via the Upload data forms endpoint, allowing an authenticated attacker with database connection update permissions to inject and execute malicious JavaScript.

EPSS

0.001

Percentile

32.6%

Related for VERACODE:38900