GHSA-m3p9-c7p3-xxmp
Dashboard / Vulnerabilities / GHSA-m3p9-c7p3-xxmp
Summary: Mayaa Cross-site Scripting vulnerability
Details: Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the default error page for the `org.seasar.mayaa.impl.engine.PageNotFoundException` exception and possibly other exceptions.
References: https://nvd.nist.gov/vuln/detail/CVE-2008-5720, https://exchange.xforce.ibmcloud.com/vulnerabilities/47623, https://github.com/seasarorg/mayaa, https://web.archive.org/web/20090622223640/http://secunia.com/advisories/33333, https://web.archive.org/web/20200301074809/http://www.securityfocus.com/bid/33015, http://jvn.jp/en/jp/JVN17298485/index.html, http://jvndb.jvn.jp/en/contents/2008/JVNDB-2008-000085.html, http://mayaa.seasar.org/news/vulnerability20081225.html
Affected packages
Package
Name: com.github.seasarorg.mayaa:mayaa
Purl: pkg:maven/com.github.seasarorg.mayaa/mayaa
Affected ranges
Type: ECOSYSTEM
Events:
