CVE-2017-12882

MEDIUM5.4EPSS 0.16%

Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality

Published: 5/17/2022Modified: 9/23/2025
Also known as:GHSA-49mj-77q5-qw5g

Description

Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (3)