Vulnerabilities
Vulnerable Software
Jeesns:  >> Jeesns  >> 1.3  Security Vulnerabilities
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
CVSS Score
5.4
EPSS Score
0.003
Published
2018-11-11
An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-12429.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-10-02


Contact Us

Shodan ® - All rights reserved