CVE-2021-36737
XSS in V3 Demo Portlet
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact
Affected products
Apache Software Foundation · Apache PortalsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →