Cross-site Scripting in Eclipse Mojarra
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 2, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Nov 3, 2022
Last updated
Feb 1, 2023
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces, allows Reflected XSS because a client window field is mishandled.
References