Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39586
HistoryMar 08, 2023 - 5:38 a.m.

Cross-site Scripting (XSS)

2023-03-0805:38:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
cross-site scripting
vulnerability
orchardcore
special characters
front end
database logs
malicious referrer

0.001 Low

EPSS

Percentile

37.7%

orchardcore is vulnerable to Cross-site Scripting (XSS) attacks. The library does not properly escape the special characters before it output to the front end, allowing an attacker to inject log entries into the database logs, containing a malicious referrer field.

0.001 Low

EPSS

Percentile

37.7%