PT-2022-11755 · W3C · W3C Unicorn

·

CVE-2021-4296

·

Published

2022-12-29

·

Updated

2024-05-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions w3c Unicorn (affected versions not specified)
Description A problematic issue has been found in w3c Unicorn, affecting the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross-site scripting. The attack may be initiated remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name 51f75c31f7fc33859a9a571311c67ae4e95d9c68. As a temporary workaround, consider disabling the ValidatorNuMessage function until a patch is available. Restrict access to the vulnerable file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java to minimize the risk of exploitation. Avoid using the argument message in the affected function until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-4296

Affected Products

W3C Unicorn