Cross-Site Scripting Vulnerability in Google Web Toolkit and JBoss Operations Network
CVE-2012-5920

Currently unrated

Key Information:

Vendor

Google

Vendor
CVE Published:
20 November 2012

What is CVE-2012-5920?

A cross-site scripting (XSS) vulnerability has been identified in Google Web Toolkit (GWT) versions 2.4 through 2.5 Final, which is integrated into JBoss Operations Network (ON) 3.1.1 and potentially other applications. This security flaw allows remote attackers to inject arbitrary web scripts or HTML into affected systems through unspecified vectors, posing a significant risk to the integrity of web applications utilizing these frameworks. The issue arises from an incomplete fix associated with a previous security concern, necessitating immediate attention from developers and system administrators.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.