CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-10544

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.1080%
EPSS Percentile7.47th
Published2020年3月13日
Last Modified2024年11月21日

Vulnerability Description

An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.

Affected Platforms (CPE)

📦
Primetek

Primefaces

= 7.0.11

References & Advisories

関連する脆弱性情報