Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40390
HistoryMay 03, 2023 - 12:36 p.m.

Cross-site Scripting (XSS)

2023-05-0312:36:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
cross-site scripting
drupal/core
javascript
cookie exfiltration
vulnerability

0.0005 Low

EPSS

Percentile

18.2%

drupal/core is vulnerable to Cross-site Scripting (XSS). The vulnerability exists due to lack of domain validations which allows an attacker to inject and execute arbitrary JavaScript which can result in cookie exfiltration.

0.0005 Low

EPSS

Percentile

18.2%