PT-2015-3451 · Jsoup+1 · Jsoup+1
Hardy Ferentschik
·
Published
2015-07-06
·
Updated
2024-08-16
·
CVE-2015-6748
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
jsoup versions prior to 1.8.3
Description
The issue is related to a lack of protection for the structure of web pages, which can be exploited to perform cross-site scripting (XSS) attacks. This allows a remote attacker to carry out XSS attacks.
Recommendations
For versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the jsoup library until a patch is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Jsoup