Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13510
HistoryMar 25, 2019 - 8:40 a.m.

Cross-Site Scripting (XSS)

2019-03-2508:40:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.959 High

EPSS

Percentile

99.5%

Apache Tomcat is vulnerable to cross-site scripting (XSS). A remote attacker is able to inject arbitrary Javascript into a victim’s browser via the time parameter in cal2.jsp to steal session tokens or perform unwanted actions on behalf of the user.

References