CVE-2021-36737

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in maven/org.apache.portals.pluto/pluto-portal

Identifiers

GHSA-x588-g38j-f672, CVE-2021-36737

Package Slug

maven/org.apache.portals.pluto/pluto-portal

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact

Affected Versions

All versions before 3.1.1

Solution

Upgrade to version 3.1.1 or above.

Last Modified

2022-01-11

source