Ververica Platform Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in Ververica Platform version 2.14.0. This issue resides within the 'Formats' feature, specifically under 'SQL -> Connectors -> Formats'. The vulnerability allows attackers to execute arbitrary web scripts.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject and execute malicious scripts in the context of the user's browser.
Reproduction
To reproduce this vulnerability, navigate to the 'Formats' feature under 'SQL -> Connectors' in Ververica Platform version 2.14.0. Once there, inject a script payload, such as an image tag with an 'onerror' event, into the URL of the 'Avro' format connector. This will trigger the execution of the injected JavaScript code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
