Lucene search

K
osvGoogleOSV:GHSA-G77G-VJJM-X83J
HistoryMay 01, 2022 - 6:26 p.m.

Apache Tomcat Example Application CSRF and XSS Vulnerabilities

2022-05-0118:26:30
Google
osv.dev
3
apache tomcat 4.1.31
example application
csrf
xss
calendar examples
remote attackers
arbitrary users
time parameter
description parameter
security vulnerabilities

AI Score

7.3

Confidence

High

EPSS

0.009

Percentile

82.3%

Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.

AI Score

7.3

Confidence

High

EPSS

0.009

Percentile

82.3%

Related for OSV:GHSA-G77G-VJJM-X83J