Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13532
HistoryMar 25, 2019 - 8:40 a.m.

Cross-Site Scripting (XSS)

2019-03-2508:40:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.004

Percentile

74.4%

apache activemq is vulnerable to cross-site scripting (XSS). A remote attacker is able to inject arbitrary Javascript into a victim’s browser via the refresh parameter to PortfolioPublishServlet.java, and through debug logs or subscribe messages in webapp/websocket/chat.js.