Описание
Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.
Пакеты
Наименование
org.springframework.batch:spring-batch-admin-manager
maven
Затронутые версииВерсия исправления
< 1.3.0.RELEASE
1.3.0.RELEASE
Связанные уязвимости
CVSS3: 5.4
nvd
больше 8 лет назад
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.