Skip to content

CVE-2014-1904 @ Maven-org.springframework:spring-webmvc-3.2.4.RELEASE #791

@cx-ronen-riesenfeld

Description

@cx-ronen-riesenfeld

Vulnerable Package issue exists @ Maven-org.springframework:spring-webmvc-3.2.4.RELEASE in branch main

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

Namespace: cxronen
Repository: BookStore
Repository Url: https://github.com/cxronen/BookStore
CxAST-Project: cxronen/BookStore
CxAST platform scan: 207c1944-f9e8-4bbb-a51e-1235c29a4b44
Branch: main
Application: BookStore
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-79


Additional Info
Remediation Upgrade Recommendation: 5.3.0


References
Advisory
Issue
Commit

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions