Apache Tomcat allows webmasters to insert xss into error messages
Moderate severity
GitHub Reviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Description
Published by the National Vulnerability Database
Dec 6, 2001
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Sep 18, 2023
Reviewed
Sep 18, 2023
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
References