Description
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
Remediation
References
https://github.com/Hurdano/JavaMelody-XSS/wiki/Attack-Vector---JavaMelody
Related Vulnerabilities
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2022-48216 Vulnerability in npm package @uniswap/universal-router
CVE-2017-16138 Vulnerability in maven package org.webjars:mime
CVE-2022-25962 Vulnerability in npm package vagrant.js
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core