Jolokia 1.3.7 is vulnerable to cross-site scripting in the HTTP servlet and allows an attacker to execute malicious JavaScript in the victim's browser.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view