Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13523
HistoryMar 25, 2019 - 8:40 a.m.

Cross-site Scripting (XSS)

2019-03-2508:40:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.032

Percentile

91.2%

The Portfolio publisher servlet in the demo web application in Apache ActiveMQ is vulnerable to cross-site scripting (XSS). The vulnerability allows remote attackers to inject arbitrary web script or HTML via the refresh parameter in demo/portfolioPublish.