PT-2020-12194 · Primetek · Primefaces
Dgusoft
·
Published
2020-03-13
·
Updated
2021-05-07
·
CVE-2020-10544
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PrimeFaces version 7.0.11
Description
A cross-site scripting (XSS) issue was discovered in the tooltip/tooltip.js component of PrimeFaces. This issue allows an attacker to provide JavaScript code in an input field, which is later used as a tooltip title without any input validation, potentially leading to the execution of malicious scripts.
Recommendations
For PrimeFaces version 7.0.11, consider validating all user input data used in tooltip titles to prevent the injection of malicious JavaScript code. As a temporary workaround, restrict the use of the tooltip feature until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Primefaces