Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-04997
HistoryJan 10, 2022 - 12:00 a.m.

Apache Pluto Cross-Site Scripting Vulnerability (CNVD-2022-04997)

2022-01-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
apache pluto
xss vulnerability
applicant mvcbean cdi
portlet
jsp version

EPSS

0.002

Percentile

57.4%

A cross-site scripting vulnerability exists in the Apache Pluto Applicant MVCBean CDI portlet, which stems from the Apache Pluto Applicant MVCBean CDI runtime environment. portlet is vulnerable to cross-site scripting (XSS) attacks in the input fields of the JSP version of the portlet. No details of the vulnerability are currently available.

EPSS

0.002

Percentile

57.4%