Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41043

Опубликовано: 24 апр. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.

An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.

This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5.

Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
Версия до 5.19.6 (исключая)
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
Версия от 6.0.0 (включая) до 6.2.5 (исключая)
cpe:2.3:a:apache:activemq_web:*:*:*:*:*:*:*:*
Версия до 5.19.6 (исключая)
cpe:2.3:a:apache:activemq_web:*:*:*:*:*:*:*:*
Версия от 6.0.0 (включая) до 6.2.5 (исключая)

EPSS

Процентиль: 43%
0.0056
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

CVSS3: 4.6
redhat
3 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

CVSS3: 6.5
debian
3 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas ...

CVSS3: 6.5
redos
4 дня назад

Уязвимость apache-activemq

CVSS3: 6.5
github
3 месяца назад

Apache ActiveMQ Vulnerable to Cross-site Scripting

EPSS

Процентиль: 43%
0.0056
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79
CWE-79