The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the link.
- https://www.first.org/cvss/calculator/3.1
- https://github.com/fkie-cad/nvd-json-data-feeds