Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7757
HistoryNov 13, 2018 - 4:38 a.m.

Cross-site Scripting (XSS)

2018-11-1304:38:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.03 Low

EPSS

Percentile

90.9%

catalina-host-manager is vulnerable to cross-site scripting (XSS) attacks. The vulnerability exists due to the lack of sanitization to the parameter passed to either the manager, html, or upload endpoints, allowing XSS attacks.

References