Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39434
HistoryFeb 27, 2023 - 2:48 a.m.

Cross-site Scripting (XSS)

2023-02-2702:48:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
cross-site scripting
vulnerability
calendar.js
placeholder field
attacker
javascript

0.001 Low

EPSS

Percentile

25.5%

baremetrics-calendar is vulnerable to Cross-site Scripting (XSS). The vulnerability exists because Calendar.js does not properly sanitize the placeholder field when creating a Calender instance which allows an attacker to inject and execute malicious JavaScript.

0.001 Low

EPSS

Percentile

25.5%

Related for VERACODE:39434