CVE-2016-0711

MEDIUM6.1EPSS 2.6%

Apache Jetspeed vulnerable to Cross-site Scripting

Published: 5/17/2022Modified: 4/14/2025
Also known as:GHSA-5pgm-9g57-3wc7

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (4)