CVE-2009-0026
Apache Jackrabbit contains Cross-site Scripting
EPSS 21.6%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
How to fix CVE-2009-0026
To remediate CVE-2009-0026, upgrade the affected package to a fixed version below.
- Maven/org.apache.jackrabbit:jackrabbit—upgrade to 1.5.2 or later
Is CVE-2009-0026 being exploited?
Moderate — EPSS is 21.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.5.2