omnifaces is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
The <o:hashParam> component writes URL fragment names and values back into a JavaScript callback in the ajax response without escaping them for a JavaScript string context. A crafted link whose fragment contains a single quote can terminate the string literal and inject arbitrary script that runs when a victim opens the page. Exploitation requires the victim to open an externally supplied link, so user interaction is needed. The fix escapes both the parameter name and value for JavaScript strings before writing them into the callback.
You are affected if you are using a version that falls within the vulnerable range and you use <o:hashParam>.
omnifaces is vulnerable to Cross-Site Scripting (XSS) in versions 3.2.0 - 3.14.22, 4.0.0 - 4.7.11 and 5.0.0 - 5.4.1.
Upgrade the org.omnifaces:omnifaces library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant