PT-2026-53740 · Apache+2 · Apache Tomcat+2
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 11.0.0-M1 through 11.0.22
Apache Tomcat versions 10.1.0-M1 through 10.1.55
Apache Tomcat versions 9.0.0.M1 through 9.0.118
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.0 through 7.0.109
Description
Cross-Site Scripting (XSS) occurs in the number guess example application due to improper neutralization of script-related HTML tags in a web page. XSS is a flaw that allows an attacker to inject malicious scripts into content delivered to other users.
Recommendations
Upgrade versions 11.0.0-M1 through 11.0.22 to 11.0.23.
Upgrade versions 10.1.0-M1 through 10.1.55 to 10.1.56.
Upgrade versions 9.0.0.M1 through 9.0.118 to 9.0.119.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Red Os
Ubuntu