Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40603
HistoryMay 19, 2023 - 9:33 a.m.

Cross-Site Scripting (XSS)

2023-05-1909:33:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
cross-site scripting
xss
easyappointments
vulnerability
user display name
sanitization
backend_header.php
arbitrary javascript
browser

EPSS

0.001

Percentile

34.5%

alextselegidis/easyappointments is vulnerable to Cross-Site Scripting (XSS). The vulnerability is due to a lack of user display name sanitization in backend_header.php, which allows an attacker to inject and execute arbitrary JavaScript into the browser.

EPSS

0.001

Percentile

34.5%