Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39194
HistoryFeb 10, 2023 - 6:33 a.m.

Cross-site Scripting (XSS)

2023-02-1006:33:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
cross-site scripting
backdrop
html validation
admin authenticated attacker
malicious javascript
user post viewing

EPSS

0.006

Percentile

78.7%

backdrop/backdrop is vulnerable to Cross-Site Scripting (XSS). The vulnerability exist due to the lack of validation in the html elements when adding a post which allows an admin authenticated attacker to inject and execute malicious JavaScript when a user views a post.

EPSS

0.006

Percentile

78.7%