Description
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
Remediation
References
https://github.com/primefaces/primefaces/issues/5642
Related Vulnerabilities
CVE-2020-7642 Vulnerability in maven package org.webjars.npm:lazysizes
CVE-2020-2170 Vulnerability in maven package org.jenkins-ci.plugins:rapiddeploy-jenkins
CVE-2020-36618 Vulnerability in npm package whois
CVE-2022-26612 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2023-22467 Vulnerability in maven package org.webjars.bowergithub.moment:luxon