Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7086
HistoryJul 18, 2018 - 2:35 a.m.

Cross-Site Scripting (XSS)

2018-07-1802:35:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.002 Low

EPSS

Percentile

58.4%

Kohana is affected by a cross-site scripting (XSS) vulnerability. This is due to the way image tags are stripped in system/classes/Kohana/Security.php, which allows an attacker to inject arbitrary Javascript code by bypassing the strip_image_tags protection mechanism.

CPENameOperatorVersion
kohana/corele3.3.6

0.002 Low

EPSS

Percentile

58.4%