Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40649
HistoryMay 24, 2023 - 1:44 a.m.

Cross-site Scripting (XSS)

2023-05-2401:44:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
cross-site scripting
apiurl
toolbar
javascript
security

EPSS

0.001

Percentile

32.5%

posthog-js is vulnerable to Cross-site Scripting (XSS). The vulnerability exists because the library does not properly sanitize the apiURL attribute in the toolbar.ts, which allows an attacker to inject and execute malicious JavaScript.

EPSS

0.001

Percentile

32.5%

Related for VERACODE:40649