Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7533
HistoryOct 01, 2018 - 2:13 a.m.

Cross-Site Scripting (XSS)

2018-10-0102:13:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

26.4%

Fork CMS is vulnerable to cross-site scripting. A remote attacker is able to inject arbitrary Javascript into a victim’s browser to steal session cookies or perform unwanted actions on behalf of the user via /backend/ajax.

EPSS

0.001

Percentile

26.4%