Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39768
HistoryMar 14, 2023 - 8:29 a.m.

Cross-site Scripting (XSS)

2023-03-1408:29:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
craftcms
xss
vulnerability
url parameters
label names
entry type
parameter.js

EPSS

0.001

Percentile

30.3%

craftcms/cms is vulnerable to Cross-site Scripting (XSS). The vulnerability exists due to improper validation of url parameters in label names or instruction of an entry type located in parameter.js, which allows an attacker to inject and execute malicious JavaScript in the victims browser.

EPSS

0.001

Percentile

30.3%

Related for VERACODE:39768