Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40232
HistoryApr 20, 2023 - 4:02 p.m.

Cross-Site Scripting (XSS)

2023-04-2016:02:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
cross-site scripting
vulnerability
sanitization
redirect url
reflection
software

EPSS

0.001

Percentile

36.1%

pay is vulnerable to Cross-Site Scripting (XSS). The vulnerability is caused by a lack of sanitization due to the back parameter in payments_controller.rb which allows an attacker to inject an arbitrary redirect URL resulting in reflected Cross-site scripting.

EPSS

0.001

Percentile

36.1%