Apache Tomcat vulnerable to Cross-site Scripting
Low severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Feb 23, 2024
Package
Affected versions
>= 4.0.0, <= 4.0.6
>= 4.1.0, <= 4.1.36
>= 5.0.0, <= 5.0.30
>= 5.5.0, <= 5.5.24
>= 6.0.0, <= 6.0.13
Patched versions
4.1.37
5.5.25
6.0.14
Description
Published by the National Vulnerability Database
Jun 14, 2007
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Feb 14, 2024
Last updated
Feb 23, 2024
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
References