CVE-2021-36738

EPSS 6.0%

Cross-site Scripting in Apache Pluto

發布日:2022/1/8修改日:2024/12/4

描述

The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact

受影響套件(1)

參考連結(3)