Lucene search

K
osvGoogleOSV:GHSA-MFHR-3XMC-R2GG
HistoryMay 17, 2022 - 1:36 a.m.

Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

2022-05-1701:36:25
Google
osv.dev
24
cross-site scripting
remote attackers
web script injection
html injection
apache activemq 5.8.0
software vulnerability

EPSS

0.012

Percentile

85.2%

Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the “cron of a message.”

EPSS

0.012

Percentile

85.2%