vendor:
Lucee
by:
Yehia Elghaly
7.5
CVSS
HIGH
Authenticated Reflected XSS
79
CWE
Product Name: Lucee
Affected Version From:
Affected Version To: 5.4.2.17
Patch Exists: NO
Related CWE:
CPE: a:lucee:lucee
Platforms Tested: Windows 10
2023
Lucee 5.4.2.17 – Authenticated Reflected XSS
The attacker can able to convince a victim to visit a malicious URL, can perform a wide variety of actions, such as stealing the victim's session token or login credentials.
Mitigation:
Implement input validation and output encoding to prevent the execution of malicious code.