Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44394
HistoryNov 28, 2023 - 12:17 a.m.

Cross-Site Scripting (XSS)

2023-11-2800:17:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
hoteldruid
cross-site scripting
vulnerability
user inputs
malicious scripts
application
validation
sanitization

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

hoteldruid is vulnerable to Cross-Site Scripting. The vulnerability due to insufficient validation or sanitization of user inputs, in the destinatario_email1 POST parameter. This allows attackers to inject and execute malicious scripts within the application.

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%