XSS in examples web application
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 6.7%
from disclosure to weapon
Published on NVDJun 23
VulnCheck+504d
exploitation probability
6.7%top 6% of all CVEs
observed exploitation
yesVulnCheck
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
Affected products
Apache Software Foundation · Apache Tomcat