CVE-2021-36739
maven/org.apache.portals.pluto/pluto-container
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The "first name" and "last name" fields of the Apache Pluto MVCBean JSP portlet maven archetype is vulnerable to Cross-Site Scripting (XSS) attacks.
Version 3.1.0
Upgrade to version 3.1.1 or above.
2022-01-13
source |