Cross-site Scripting Vulnerability in Apache Jetspeed by Apache
CVE-2016-0712
6.1MEDIUM
What is CVE-2016-0712?
A Cross-site scripting (XSS) vulnerability exists in Apache Jetspeed prior to version 2.3.1. This flaw allows remote attackers to inject arbitrary web scripts or HTML via the PATH_INFO variable to the portal. Such exploitation could lead to unauthorized actions being performed on behalf of the user or exposure of sensitive information, severely compromising web application security.