Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mojarra 跨站脚本漏洞
Vulnerability Description
Mojarra是一款JavaServer Faces规范的实现。 Eclipse Mojarra中的faces/context/PartialViewContextImpl.java文件存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。以下产品及版本受到影响:Eclipse Mojarra 2.3.10之前版本;Oracle Mojarra JavaServer Faces 2.2.20之前版本。
CVSS Information
N/A
Vulnerability Type
N/A