PT-2022-10542 · Apache · Apache Pluto
Neil Griffin
·
Published
2022-01-06
·
Updated
2022-01-12
·
CVE-2021-36739
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Pluto version 3.1.0
Description
The issue concerns Cross-Site Scripting (XSS) attacks, which occur when an attacker injects malicious code into a website, allowing them to steal user data or take control of the user's session. In this case, the
first name and last name fields of the Apache Pluto MVCBean JSP portlet maven archetype are vulnerable to such attacks.Recommendations
For Apache Pluto version 3.1.0, consider validating and sanitizing user input for the
first name and last name fields to prevent XSS attacks. As a temporary workaround, restrict user input to only allow expected characters and formats for these fields until a patch is available.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Pluto