Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4664
HistoryJul 25, 2017 - 7:30 p.m.

Cross-site Scripting (XSS)

2017-07-2519:30:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.012 Low

EPSS

Percentile

85.0%

concrete5 is vulnerable to cross-site scripting (XSS) attacks. The library fails to sanitize user input to bulkupdate.php and sitemap_drag_request.php, allowing a malicious user to inject and execute arbitrary script.

CPENameOperatorVersion
concrete5/concrete5le5.7.2.1

0.012 Low

EPSS

Percentile

85.0%

Related for VERACODE:4664