Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13528
HistoryMar 25, 2019 - 8:40 a.m.

Cross-Site Scripting (XSS)

2019-03-2508:40:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.103 Low

EPSS

Percentile

95.0%

Apache Tomcat is vulnerable to cross-site scripting (XSS). The appdev/sample/web/hello.jsp example application does not sanitize the user provided input, allowing a remote attacker to inject malicious web script or HTML into a victim’s browser via the test parameter.

References