Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39587
HistoryMar 08, 2023 - 7:00 a.m.

Cross-site Scripting (XSS)

2023-03-0807:00:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
cross-site scripting
directus
vulnerability
javascript
email

EPSS

0.001

Percentile

29.7%

directus is vulnerable to Cross-site Scripting (XSS). The vulnerability is due to allow-listed reset URLs through the query parameters, which allows the attacker to inject and execute malicious JavaScript into the browser through an email.

EPSS

0.001

Percentile

29.7%

Related for VERACODE:39587