spring-webmvc is vulnerable to Cross-site Scripting (XSS)
59
Medium Risk
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form:*> tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability.
You are affected if you are using a version that falls within the vulnerable range and if the application uses the JSP form:*> tags with user-supplied values for the cssClass, cssErrorClass, or cssStyle attributes.
spring-webmvc is vulnerable to Cross-site Scripting (XSS) in versions 5.3.0 - 7.0.7 and 6.2.0 - 6.2.18.
Upgrade the org.springframework:spring-webmvc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.