CVE-2017-12882

MEDIUM5.4EPSS 0.16%

Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality

發布日:2022/5/17修改日:2025/9/23

描述

Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

參考連結(3)