PT-2026-107178 · Apache · Apache Commons Bcel
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Commons BCEL versions prior to 6.13.0
Description
Improper neutralization of input during web page generation leads to cross-site scripting (XSS), a condition where malicious scripts are injected into trusted websites. This occurs when using the
Class2HTML emitter to generate webpages from class files that may be controlled by an attacker, as the emitter writes class-file strings into HTML without proper escaping, resulting in stored XSS in the reports.Recommendations
Upgrade to version 6.13.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Commons Bcel