Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6280
HistoryMay 11, 2018 - 9:03 a.m.

Cross-site Scripting (XSS)

2018-05-1109:03:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

51.7%

drupal/drupal is vulnerable to cross-site scripting (XSS) attacks. The checkPlain function doesn’t properly sanitize escape characters, allowing a malicious user to inject and execute arbitrary Javascript.

CPENameOperatorVersion
drupal/drupalle8.4.4
drupal/corele8.4.4