Reflected Cross-Site Scripting in Oracle GlassFish Server
CVE-2021-3314
6.1MEDIUM
What is CVE-2021-3314?
Oracle GlassFish Server versions 3.1.2.18 and earlier are vulnerable to reflected cross-site scripting (XSS) attacks due to flaws in the handling of the log viewer page. An attacker can exploit this vulnerability by crafting a malicious URL that, when visited by an administrator, injects dangerous content. The content is reflected back and executed in the browser, potentially compromising user sessions and data. This vulnerability is notably significant as it affects products that are no longer maintained, emphasizing the importance of regular updates and security patches.