PT-2023-6900 · Unknown · Net.Sourceforge.Htmlunit:Htmlunit

Siebene

·

Published

2023-04-03

·

Updated

2026-05-25

·

CVE-2023-26119

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions net.sourceforge.htmlunit:htmlunit versions 0 through 3.0.0
Description The issue is related to incorrect code generation management in the HtmlUnit browser, which can be exploited to execute arbitrary code remotely via XSTL when browsing an attacker's webpage. This can allow a remote attacker to execute arbitrary code.
Recommendations For versions 0 through 3.0.0, update to a version later than 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to web pages that may exploit this vulnerability until a patch is available.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2023-07918
CVE-2023-26119
GHSA-3XRR-7M6P-P7XH

Affected Products

Net.Sourceforge.Htmlunit:Htmlunit