QID 996031
Date Published: 2023-11-27
QID 996031: Java (Maven) Security Update for org.primefaces:primefaces (GHSA-fw5f-7c6c-3vmv)
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fw5f-7c6c-3vmv for updates and patch information.
Vendor References
- GHSA-fw5f-7c6c-3vmv -
github.com/advisories/GHSA-fw5f-7c6c-3vmv
CVEs related to QID 996031
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fw5f-7c6c-3vmv | org.primefaces:primefaces |
|