Code Injection
The RichFaces Framework is vulnerable to Expression Language (EL) injection via the UserResource resource.
The RichFaces Framework is vulnerable to Expression Language (EL) injection via the UserResource resource.
JBoss RichFaces allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code.
JBoss RichFaces allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code.