Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6427
HistoryMay 30, 2018 - 6:19 a.m.

Cross-site Scripting (XSS)

2018-05-3006:19:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

38.0%

sexstatic is vulnerable to cross-site scripting (XSS) attacks. The vulnerability exists due to the lack of sanitization in user input of pathname in showdir.js, allowing arbitrary javascript code to be executed when rendered.

EPSS

0.001

Percentile

38.0%