PT-2023-6900 · Unknown · Net.Sourceforge.Htmlunit:Htmlunit
Siebene
·
Published
2023-04-03
·
Updated
2026-05-25
·
CVE-2023-26119
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
net.sourceforge.htmlunit:htmlunit versions 0 through 3.0.0
Description
The issue is related to incorrect code generation management in the HtmlUnit browser, which can be exploited to execute arbitrary code remotely via XSTL when browsing an attacker's webpage. This can allow a remote attacker to execute arbitrary code.
Recommendations
For versions 0 through 3.0.0, update to a version later than 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to web pages that may exploit this vulnerability until a patch is available.
Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Net.Sourceforge.Htmlunit:Htmlunit