Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8097
HistoryDec 31, 2018 - 2:39 a.m.

Cross-Site Scripting (XSS)

2018-12-3102:39:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.001 Low

EPSS

Percentile

32.9%

hsweb-system-workflow-local is vulnerable to cross-site scripting (XSS). A lack of validation on the type parameter in FlowableModelManagerController.java allows a remote attacker to inject arbitrary Javascript into a victim’s browser to steal session token or perform unwanted actions on behalf of the user.

CPENameOperatorVersion
hsweb-system-workflow-localle3.0.4

0.001 Low

EPSS

Percentile

32.9%

Related for VERACODE:8097