QID 982642
QID 982642: Nodejs (npm) Security Update for primefaces (GHSA-fw5f-7c6c-3vmv)
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fw5f-7c6c-3vmv for updates pertaining to this vulnerability.
Vendor References
- GHSA-fw5f-7c6c-3vmv -
github.com/advisories/GHSA-fw5f-7c6c-3vmv
CVEs related to QID 982642
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fw5f-7c6c-3vmv | primefaces |
|