Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42810
HistoryAug 16, 2023 - 12:42 a.m.

Cross Site Scripting (XSS)

2023-08-1600:42:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
cross site scripting
svelecte
dropdown
vulnerability
dynamic content

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

27.1%

svelecte is vulnerable to Cross Site Scripting (XSS). The vulnerability occurs when a user enters a specially crafted item name in the Svelte dropdown. Sites using Svelecte with dynamically created items from external or user-created content may be vulnerable to XSS attacks and clickjacking.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

27.1%

Related for VERACODE:42810