Description
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
Remediation
References
https://github.com/Hurdano/JavaMelody-XSS/wiki/Attack-Vector---JavaMelody
Related Vulnerabilities
CVE-2020-7742 Vulnerability in npm package simpl-schema
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2021-4264 Vulnerability in maven package org.webjars.npm:dustjs-linkedin
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-hadoop-dbcp-service
CVE-2018-17420 Vulnerability in maven package com.zrlog:zrlog