Lucene search

K
osvGoogleOSV:GHSA-58HJ-575G-5J25
HistoryApr 30, 2022 - 6:16 p.m.

Apache Tomcat allows webmasters to insert xss into error messages

2022-04-3018:16:47
Google
osv.dev
2
apache
tomcat
xss
vulnerability
javascript
error message

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

38.1%

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

38.1%

Related for OSV:GHSA-58HJ-575G-5J25