PT-2022-11755 · W3C · W3C Unicorn
Echo0X00
·
Published
2022-12-29
·
Updated
2024-05-17
·
CVE-2021-4296
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
w3c Unicorn (affected versions not specified)
Description
A problematic issue has been found in w3c Unicorn, affecting the function
ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross-site scripting. The attack may be initiated remotely.Recommendations
To fix this issue, it is recommended to apply a patch with the name
51f75c31f7fc33859a9a571311c67ae4e95d9c68. As a temporary workaround, consider disabling the ValidatorNuMessage function until a patch is available. Restrict access to the vulnerable file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java to minimize the risk of exploitation. Avoid using the argument message in the affected function until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
W3C Unicorn